New Armored Likho tools target Telegram and eavesdropping
The Armored Likho group launched a cyber-espionage campaign in May 2026 targeting private individuals and organizations in Russia, including corporations, public sector, IT companies, and educational institutions. The attackers used fake donation service applications to initiate infections. They deployed the Still Toolkit, a Rust-based malware suite with two components: Still Sync, which steals Telegram session data to extract chat logs, media, and account info via the Telegram API; and Still Audio, which conducts covert audio surveillance by analyzing audio streams, detecting speech, recording conversations, and sending data to command-and-control servers. This campaign shows advanced capabilities and reuse of infrastructure and encryption methods from prior operations.
AI Analysis
Technical Summary
In May 2026, the Armored Likho cyber-espionage group targeted multiple sectors in Russia using fake donation service apps as infection vectors. They deployed the Still Toolkit, developed in Rust, consisting of Still Sync and Still Audio components. Still Sync enables automated theft of Telegram session data, allowing extraction of chat logs, media files, and account information through the Telegram API. Still Audio performs covert audio surveillance by analyzing incoming audio streams, detecting speech patterns, recording conversations, and transmitting them to attacker-controlled servers. The campaign reflects an evolution in the group's operational capabilities, leveraging shared infrastructure and encryption techniques consistent with their previous campaigns.
Potential Impact
The campaign compromises the confidentiality of Telegram communications by stealing session data and extracting chat logs, media, and account information. Additionally, it enables covert audio surveillance by recording and exfiltrating conversations, posing significant privacy and intelligence risks to targeted individuals and organizations. The targeting of diverse sectors including major corporations and public entities in Russia indicates potential for sensitive information exposure and espionage.
Mitigation Recommendations
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on preventing initial infection by avoiding installation of untrusted applications, especially fake donation service apps. Monitoring for indicators of compromise related to the Still Toolkit and restricting unauthorized access to Telegram session data can help reduce risk. Incident response should include forensic analysis to detect and remove the malware if infection is suspected.
Affected Countries
Russia
Indicators of Compromise
- ip: 213.252.244.123
- ip: 159.198.37.74
- ip: 23.26.237.250
- ip: 23.27.24.30
- ip: 145.223.69.143
- ip: 145.223.68.66
- hash: c1d1ee16b92e6a138ffa048855f75d7d
- hash: 17674b250d8b422a50a86c9ff207186d
- hash: 62801f6223e860a7cca271522e303b2d
- hash: 68f0365d2fa8c828d012d8859e52a773
- hash: 4bd7c352ae277b0e38d07beedd4dd507
- hash: d4bc09fb10ea2a5dc0bcbeeda5e5afdd
- hash: 2ca8adbab98ebe305eacf272cf48f5a0
- hash: 3ac41b097236a7723821848ae31ef141
- hash: 439255736797bc88bd19f282449e0436
- hash: 17b6f4984930165939680a09d91989ad82bc57e2
- hash: 724f6ca2ea66dbf117c7eea42c99760716ec75b9
- hash: b9258c816724cb074258df485dfbc5b08141cdcb
- hash: dd1f41f6f8e995fb482070d6689f4238505aac78
- hash: 31349d61da780d59a8a27e2762405632726d88135a08ac5dda05849c62dfd551
- hash: 404eb4ada6e161210611f1c8275f126ec24aad37c380ead130cf15667023d249
- hash: 4eb6126f7e23d9155df280b944a98da10a79f1067f39990cf019f25feef75712
- hash: 5fc1251e474eae9253362a08095e989edc2b63de21d76052a2c849efc6792c3f
- url: https://srwinservice.com
- url: https://tg4service.com:443
- domain: still.rpc.audio
New Armored Likho tools target Telegram and eavesdropping
Description
The Armored Likho group launched a cyber-espionage campaign in May 2026 targeting private individuals and organizations in Russia, including corporations, public sector, IT companies, and educational institutions. The attackers used fake donation service applications to initiate infections. They deployed the Still Toolkit, a Rust-based malware suite with two components: Still Sync, which steals Telegram session data to extract chat logs, media, and account info via the Telegram API; and Still Audio, which conducts covert audio surveillance by analyzing audio streams, detecting speech, recording conversations, and sending data to command-and-control servers. This campaign shows advanced capabilities and reuse of infrastructure and encryption methods from prior operations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In May 2026, the Armored Likho cyber-espionage group targeted multiple sectors in Russia using fake donation service apps as infection vectors. They deployed the Still Toolkit, developed in Rust, consisting of Still Sync and Still Audio components. Still Sync enables automated theft of Telegram session data, allowing extraction of chat logs, media files, and account information through the Telegram API. Still Audio performs covert audio surveillance by analyzing incoming audio streams, detecting speech patterns, recording conversations, and transmitting them to attacker-controlled servers. The campaign reflects an evolution in the group's operational capabilities, leveraging shared infrastructure and encryption techniques consistent with their previous campaigns.
Potential Impact
The campaign compromises the confidentiality of Telegram communications by stealing session data and extracting chat logs, media, and account information. Additionally, it enables covert audio surveillance by recording and exfiltrating conversations, posing significant privacy and intelligence risks to targeted individuals and organizations. The targeting of diverse sectors including major corporations and public entities in Russia indicates potential for sensitive information exposure and espionage.
Defensive Guidance
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on preventing initial infection by avoiding installation of untrusted applications, especially fake donation service apps. Monitoring for indicators of compromise related to the Still Toolkit and restricting unauthorized access to Telegram session data can help reduce risk. Incident response should include forensic analysis to detect and remove the malware if infection is suspected.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/armored-likho-still-toolkit/121033"]
- Adversary
- Armored Likho
- Pulse Id
- 6a7da6ccbbdd8552713c76a1
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip213.252.244.123 | — | |
ip159.198.37.74 | — | |
ip23.26.237.250 | — | |
ip23.27.24.30 | — | |
ip145.223.69.143 | — | |
ip145.223.68.66 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashc1d1ee16b92e6a138ffa048855f75d7d | — | |
hash17674b250d8b422a50a86c9ff207186d | — | |
hash62801f6223e860a7cca271522e303b2d | — | |
hash68f0365d2fa8c828d012d8859e52a773 | — | |
hash4bd7c352ae277b0e38d07beedd4dd507 | — | |
hashd4bc09fb10ea2a5dc0bcbeeda5e5afdd | — | |
hash2ca8adbab98ebe305eacf272cf48f5a0 | — | |
hash3ac41b097236a7723821848ae31ef141 | — | |
hash439255736797bc88bd19f282449e0436 | — | |
hash17b6f4984930165939680a09d91989ad82bc57e2 | — | |
hash724f6ca2ea66dbf117c7eea42c99760716ec75b9 | — | |
hashb9258c816724cb074258df485dfbc5b08141cdcb | — | |
hashdd1f41f6f8e995fb482070d6689f4238505aac78 | — | |
hash31349d61da780d59a8a27e2762405632726d88135a08ac5dda05849c62dfd551 | — | |
hash404eb4ada6e161210611f1c8275f126ec24aad37c380ead130cf15667023d249 | — | |
hash4eb6126f7e23d9155df280b944a98da10a79f1067f39990cf019f25feef75712 | — | |
hash5fc1251e474eae9253362a08095e989edc2b63de21d76052a2c849efc6792c3f | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://srwinservice.com | — | |
urlhttps://tg4service.com:443 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainstill.rpc.audio | — |
Threat ID: 6a7dc5f5bf8831d5393e2bfd
Added to database: 08/13/2026, 13:26:13 UTC
Last enriched: 08/13/2026, 17:31:31 UTC
Last updated: 08/13/2026, 17:31:31 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.