Skip to main content

New Armored Likho tools target Telegram and eavesdropping

0
Medium
Published: 08/14/2026 (08/14/2026, 10:35:18 UTC)
Source: AlienVault OTX General

Description

In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 17:31:31 UTC

Technical Analysis

In May 2026, the Armored Likho cyber-espionage group targeted multiple sectors in Russia using fake donation service apps as infection vectors. They deployed the Still Toolkit, developed in Rust, consisting of Still Sync and Still Audio components. Still Sync enables automated theft of Telegram session data, allowing extraction of chat logs, media files, and account information through the Telegram API. Still Audio performs covert audio surveillance by analyzing incoming audio streams, detecting speech patterns, recording conversations, and transmitting them to attacker-controlled servers. The campaign reflects an evolution in the group's operational capabilities, leveraging shared infrastructure and encryption techniques consistent with their previous campaigns.

Potential Impact

The campaign compromises the confidentiality of Telegram communications by stealing session data and extracting chat logs, media, and account information. Additionally, it enables covert audio surveillance by recording and exfiltrating conversations, posing significant privacy and intelligence risks to targeted individuals and organizations. The targeting of diverse sectors including major corporations and public entities in Russia indicates potential for sensitive information exposure and espionage.

Defensive Guidance

No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on preventing initial infection by avoiding installation of untrusted applications, especially fake donation service apps. Monitoring for indicators of compromise related to the Still Toolkit and restricting unauthorized access to Telegram session data can help reduce risk. Incident response should include forensic analysis to detect and remove the malware if infection is suspected.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/armored-likho-still-toolkit/121033"]
Adversary
Armored Likho
Pulse Id
6a7da6ccbbdd8552713c76a1

Indicators of Compromise

Ip

ValueDescriptionCopy
ip213.252.244.123
—
ip159.198.37.74
—
ip23.26.237.250
—
ip23.27.24.30
—
ip145.223.69.143
—
ip145.223.68.66
—

Hash

ValueDescriptionCopy
hashc1d1ee16b92e6a138ffa048855f75d7d
—
hash17674b250d8b422a50a86c9ff207186d
—
hash62801f6223e860a7cca271522e303b2d
—
hash68f0365d2fa8c828d012d8859e52a773
—
hash4bd7c352ae277b0e38d07beedd4dd507
—
hashd4bc09fb10ea2a5dc0bcbeeda5e5afdd
—
hash2ca8adbab98ebe305eacf272cf48f5a0
—
hash3ac41b097236a7723821848ae31ef141
—
hash439255736797bc88bd19f282449e0436
—
hash17b6f4984930165939680a09d91989ad82bc57e2
—
hash724f6ca2ea66dbf117c7eea42c99760716ec75b9
—
hashb9258c816724cb074258df485dfbc5b08141cdcb
—
hashdd1f41f6f8e995fb482070d6689f4238505aac78
—
hash31349d61da780d59a8a27e2762405632726d88135a08ac5dda05849c62dfd551
—
hash404eb4ada6e161210611f1c8275f126ec24aad37c380ead130cf15667023d249
—
hash4eb6126f7e23d9155df280b944a98da10a79f1067f39990cf019f25feef75712
—
hash5fc1251e474eae9253362a08095e989edc2b63de21d76052a2c849efc6792c3f
—

Url

ValueDescriptionCopy
urlhttps://srwinservice.com
—
urlhttps://tg4service.com:443
—

Domain

ValueDescriptionCopy
domainstill.rpc.audio
—

Threat ID: 6a7dc5f5bf8831d5393e2bfd

Added to database: 08/13/2026, 13:26:13 UTC

Last enriched: 08/13/2026, 17:31:31 UTC

Last updated: 09/26/2026, 18:14:28 UTC

Views: 125

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses