In May 2026, a new cyber-espionage campaign attributed to the Armored Likho group, also known as Eagle Werewolf, was uncovered. This campaign targets a wide range of private individuals and organizations across various sectors in Russia, including major corporations, the public sector, IT, and education. The attackers employed a deceptive application that masquerades as a donation service to lure victims. However, the most notable aspect of this campaign is not the initial infection method but rather the sophisticated malicious implants utilized for cyber-espionage. The research team at Kaspersky has detailed these developments in their findings, which can be explored further on their website.
The Armored Likho group has previously been linked to various cyber-attacks, with their recent activities showing significant overlap with earlier campaigns from February and November 2024. The current campaign, however, marks a notable expansion of their toolkit, introducing new capabilities that enhance their espionage efforts.
New Cyber-Espionage Toolkit: The Still Toolkit
At the core of this campaign is the newly discovered Still Toolkit, developed in Rust. This toolkit comprises two primary components: Still Sync and Still Audio. Still Sync is designed to steal Telegram session data, allowing attackers to maintain ongoing access to victims’ accounts. By leveraging the Telegram API, the attackers can automatically extract chat logs, media files, and other sensitive information.
The second component, Still Audio, serves a different purpose: it enables covert audio surveillance. This implant analyzes incoming audio streams, detects speech, records conversations, and transmits these recordings to a command-and-control (C2) server. The technical sophistication of these tools highlights the evolving nature of cyber-espionage tactics employed by the Armored Likho group.
Initial Infection Method
The infection process begins with the distribution of a fake app that mimics a donation service. Although the exact distribution method remains unclear, several samples posing as legitimate applications from various Russian foundations have been identified. Once launched, the app presents a login form requesting a password, which is likely provided by the attackers. After entering a valid password, users are presented with a catalog of items available for donation, while the dropper silently decrypts and executes the payload in the background.
Technical Details of Still Sync
Still Sync operates as an asynchronous application utilizing the Tokio library for its architecture. It communicates with the C2 server via gRPC and employs FlatBuffers for message serialization. The implant collects critical system information, including motherboard serial number, CPU ID, and BIOS serial number, which it hashes and sends to the C2 server for registration.
Once registered, Still Sync can execute various commands based on settings retrieved from the server, including the ability to extract Telegram data. The module searches for the tdata folder, which contains session data, and can employ multiple methods to access this information, even bypassing standard access controls if necessary.
Capabilities of Still Audio
Still Audio mirrors the functionality of Still Sync but focuses on audio surveillance. Upon launch, it extracts a library for encoding audio data and registers with the C2 server. The implant employs a Voice Activity Detection (VAD) algorithm to determine when to start and stop recording based on audio levels. Interestingly, it does not attempt to conceal its presence, appearing in Windows settings under the name “Intel Audio.” Recorded audio is encoded and sent to the C2 server for further analysis.
Infrastructure and Victims
The infrastructure supporting this campaign is diverse, utilizing various hosting providers and domains to complicate detection efforts. The primary targets of this campaign are users in Russia, with a focus on private individuals, corporate entities, government organizations, IT companies, and educational institutions.
Conclusion
The emergence of the Still Toolkit signifies a significant evolution in the Armored Likho group’s cyber-espionage capabilities. By integrating advanced modules for data extraction and audio surveillance, the group enhances its ability to gather intelligence from compromised systems. This development underscores the need for heightened vigilance and robust security measures to counteract such sophisticated threats.
For further details on this threat and indicators of compromise, refer to the comprehensive report by Kaspersky.
Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.


