The cyber-espionage group Armored Likho is targeting Russian individuals and organizations with a new Rust-based toolkit designed to steal Telegram data and conduct covert audio surveillance.
Key Points
- The campaign uses fake donation apps as droppers to deploy the "Still Toolkit," which includes the Still Sync and Still Audio modules.
- Still Sync extracts Telegram session data, chat logs, and media files by leveraging the Telegram API and stolen account credentials.
- Still Audio performs voice-activated surveillance by recording audio when it detects speech, then exfiltrating the files to a command-and-control server.
- Attackers utilize the Tauri framework for the initial dropper and employ sophisticated techniques like the Dead Drop Resolver to maintain persistent access.
- Kaspersky identifies these threats as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.
Why it Matters
- This campaign demonstrates a significant evolution in Armored Likho’s capabilities, moving beyond simple data theft to active, multi-channel intelligence gathering. The development of a cohesive, modular ecosystem suggests the group is refining its tools for long-term, high-impact espionage against both private and public sector targets.