Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New Armored Likho tools target Telegram and eavesdropping

0
Medium
Published: 08/13/2026 (08/13/2026, 11:13:16 UTC)
Source: AlienVault OTX General

Description

The Armored Likho group launched a cyber-espionage campaign in May 2026 targeting private individuals and organizations in Russia, including corporations, public sector, IT companies, and educational institutions. The attackers used fake donation service applications to initiate infections. They deployed the Still Toolkit, a Rust-based malware suite with two components: Still Sync, which steals Telegram session data to extract chat logs, media, and account info via the Telegram API; and Still Audio, which conducts covert audio surveillance by analyzing audio streams, detecting speech, recording conversations, and sending data to command-and-control servers. This campaign shows advanced capabilities and reuse of infrastructure and encryption methods from prior operations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 17:31:31 UTC

Technical Analysis

In May 2026, the Armored Likho cyber-espionage group targeted multiple sectors in Russia using fake donation service apps as infection vectors. They deployed the Still Toolkit, developed in Rust, consisting of Still Sync and Still Audio components. Still Sync enables automated theft of Telegram session data, allowing extraction of chat logs, media files, and account information through the Telegram API. Still Audio performs covert audio surveillance by analyzing incoming audio streams, detecting speech patterns, recording conversations, and transmitting them to attacker-controlled servers. The campaign reflects an evolution in the group's operational capabilities, leveraging shared infrastructure and encryption techniques consistent with their previous campaigns.

Potential Impact

The campaign compromises the confidentiality of Telegram communications by stealing session data and extracting chat logs, media, and account information. Additionally, it enables covert audio surveillance by recording and exfiltrating conversations, posing significant privacy and intelligence risks to targeted individuals and organizations. The targeting of diverse sectors including major corporations and public entities in Russia indicates potential for sensitive information exposure and espionage.

Defensive Guidance

No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Defenders should focus on preventing initial infection by avoiding installation of untrusted applications, especially fake donation service apps. Monitoring for indicators of compromise related to the Still Toolkit and restricting unauthorized access to Telegram session data can help reduce risk. Incident response should include forensic analysis to detect and remove the malware if infection is suspected.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/armored-likho-still-toolkit/121033"]
Adversary
Armored Likho
Pulse Id
6a7da6ccbbdd8552713c76a1
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip213.252.244.123
ip159.198.37.74
ip23.26.237.250
ip23.27.24.30
ip145.223.69.143
ip145.223.68.66

Hash

ValueDescriptionCopy
hashc1d1ee16b92e6a138ffa048855f75d7d
hash17674b250d8b422a50a86c9ff207186d
hash62801f6223e860a7cca271522e303b2d
hash68f0365d2fa8c828d012d8859e52a773
hash4bd7c352ae277b0e38d07beedd4dd507
hashd4bc09fb10ea2a5dc0bcbeeda5e5afdd
hash2ca8adbab98ebe305eacf272cf48f5a0
hash3ac41b097236a7723821848ae31ef141
hash439255736797bc88bd19f282449e0436
hash17b6f4984930165939680a09d91989ad82bc57e2
hash724f6ca2ea66dbf117c7eea42c99760716ec75b9
hashb9258c816724cb074258df485dfbc5b08141cdcb
hashdd1f41f6f8e995fb482070d6689f4238505aac78
hash31349d61da780d59a8a27e2762405632726d88135a08ac5dda05849c62dfd551
hash404eb4ada6e161210611f1c8275f126ec24aad37c380ead130cf15667023d249
hash4eb6126f7e23d9155df280b944a98da10a79f1067f39990cf019f25feef75712
hash5fc1251e474eae9253362a08095e989edc2b63de21d76052a2c849efc6792c3f

Url

ValueDescriptionCopy
urlhttps://srwinservice.com
urlhttps://tg4service.com:443

Domain

ValueDescriptionCopy
domainstill.rpc.audio

Threat ID: 6a7dc5f5bf8831d5393e2bfd

Added to database: 08/13/2026, 13:26:13 UTC

Last enriched: 08/13/2026, 17:31:31 UTC

Last updated: 08/13/2026, 17:31:31 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses