AUTO-UPDATED

Armored Likho expands its cyber-espionage toolkit

The cyber-espionage group Armored Likho is targeting Russian individuals and organizations with a new Rust-based toolkit designed to steal Telegram data and conduct covert audio surveillance.

Key Points

  • The campaign uses fake donation apps as droppers to deploy the "Still Toolkit," which includes the Still Sync and Still Audio modules.
  • Still Sync extracts Telegram session data, chat logs, and media files by leveraging the Telegram API and stolen account credentials.
  • Still Audio performs voice-activated surveillance by recording audio when it detects speech, then exfiltrating the files to a command-and-control server.
  • Attackers utilize the Tauri framework for the initial dropper and employ sophisticated techniques like the Dead Drop Resolver to maintain persistent access.
  • Kaspersky identifies these threats as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.

Why it Matters

  • This campaign demonstrates a significant evolution in Armored Likho’s capabilities, moving beyond simple data theft to active, multi-channel intelligence gathering. The development of a cohesive, modular ecosystem suggests the group is refining its tools for long-term, high-impact espionage against both private and public sector targets.
Securelist.com Published by Konstantin Isakov
Read original