Armored Likho Group Expands Cyber-Espionage Toolkit with Still Sync and Still Audio Modules

Published:

spot_img

In May 2026, a new cyber-espionage campaign attributed to the Armored Likho group, also known as Eagle Werewolf, was uncovered. This campaign targets a wide range of private individuals and organizations across various sectors in Russia, including major corporations, the public sector, IT, and education. The attackers employed a deceptive application that masquerades as a donation service to lure victims. However, the most notable aspect of this campaign is not the initial infection method but rather the sophisticated malicious implants utilized for cyber-espionage. The research team at Kaspersky has detailed these developments in their findings, which can be explored further on their website.

The Armored Likho group has previously been linked to various cyber-attacks, with their recent activities showing significant overlap with earlier campaigns from February and November 2024. The current campaign, however, marks a notable expansion of their toolkit, introducing new capabilities that enhance their espionage efforts.

New Cyber-Espionage Toolkit: The Still Toolkit

At the core of this campaign is the newly discovered Still Toolkit, developed in Rust. This toolkit comprises two primary components: Still Sync and Still Audio. Still Sync is designed to steal Telegram session data, allowing attackers to maintain ongoing access to victims’ accounts. By leveraging the Telegram API, the attackers can automatically extract chat logs, media files, and other sensitive information.

The second component, Still Audio, serves a different purpose: it enables covert audio surveillance. This implant analyzes incoming audio streams, detects speech, records conversations, and transmits these recordings to a command-and-control (C2) server. The technical sophistication of these tools highlights the evolving nature of cyber-espionage tactics employed by the Armored Likho group.

Initial Infection Method

The infection process begins with the distribution of a fake app that mimics a donation service. Although the exact distribution method remains unclear, several samples posing as legitimate applications from various Russian foundations have been identified. Once launched, the app presents a login form requesting a password, which is likely provided by the attackers. After entering a valid password, users are presented with a catalog of items available for donation, while the dropper silently decrypts and executes the payload in the background.

Technical Details of Still Sync

Still Sync operates as an asynchronous application utilizing the Tokio library for its architecture. It communicates with the C2 server via gRPC and employs FlatBuffers for message serialization. The implant collects critical system information, including motherboard serial number, CPU ID, and BIOS serial number, which it hashes and sends to the C2 server for registration.

Once registered, Still Sync can execute various commands based on settings retrieved from the server, including the ability to extract Telegram data. The module searches for the tdata folder, which contains session data, and can employ multiple methods to access this information, even bypassing standard access controls if necessary.

Capabilities of Still Audio

Still Audio mirrors the functionality of Still Sync but focuses on audio surveillance. Upon launch, it extracts a library for encoding audio data and registers with the C2 server. The implant employs a Voice Activity Detection (VAD) algorithm to determine when to start and stop recording based on audio levels. Interestingly, it does not attempt to conceal its presence, appearing in Windows settings under the name “Intel Audio.” Recorded audio is encoded and sent to the C2 server for further analysis.

Infrastructure and Victims

The infrastructure supporting this campaign is diverse, utilizing various hosting providers and domains to complicate detection efforts. The primary targets of this campaign are users in Russia, with a focus on private individuals, corporate entities, government organizations, IT companies, and educational institutions.

Conclusion

The emergence of the Still Toolkit signifies a significant evolution in the Armored Likho group’s cyber-espionage capabilities. By integrating advanced modules for data extraction and audio surveillance, the group enhances its ability to gather intelligence from compromised systems. This development underscores the need for heightened vigilance and robust security measures to counteract such sophisticated threats.

For further details on this threat and indicators of compromise, refer to the comprehensive report by Kaspersky.

Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.

spot_img

Related articles

Recent articles

Terabytes of credentials compromised in LiteLLM supply-chain attack affecting thousands of organizations

A massive supply-chain attack has compromised terabytes of credentials, affecting thousands of organizations globally. The breach, linked to the LiteLLM environment, has prompted urgent...

UAE Cybersecurity Council launches new initiative to combat AI-enabled threats

Dubai — The UAE is taking significant strides in enhancing its cybersecurity landscape with the recent launch of a new initiative by the UAE...

737 Chrome VPN Extensions Found Routing Traffic Through Proxies, Targeting Users

A recent investigation has uncovered a significant security threat involving 737 free VPN and proxy extensions on the Chrome Web Store, primarily targeting Russian-speaking...

Lazarus Group Exploits Windows Zero-Day Vulnerability to Deploy Backdoor Targeting Defense Firms Worldwide

The North Korean threat actor known as Lazarus Group has exploited a newly patched zero-day vulnerability in Microsoft Windows to deploy a previously unseen...