Armored Likho Group Expands Cyber-Espionage Toolkit with Still Sync and Still Audio Modules

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

In May 2026, a new cyber-espionage campaign attributed to the Armored Likho group, also known as Eagle Werewolf, was uncovered. This campaign targets a wide range of private individuals and organizations across various sectors in Russia, including major corporations, the public sector, IT, and education. The attackers employed a deceptive application that masquerades as a donation service to lure victims. However, the most notable aspect of this campaign is not the initial infection method but rather the sophisticated malicious implants utilized for cyber-espionage. The research team at Kaspersky has detailed these developments in their findings, which can be explored further on their website.

The Armored Likho group has previously been linked to various cyber-attacks, with their recent activities showing significant overlap with earlier campaigns from February and November 2024. The current campaign, however, marks a notable expansion of their toolkit, introducing new capabilities that enhance their espionage efforts.

New Cyber-Espionage Toolkit: The Still Toolkit

At the core of this campaign is the newly discovered Still Toolkit, developed in Rust. This toolkit comprises two primary components: Still Sync and Still Audio. Still Sync is designed to steal Telegram session data, allowing attackers to maintain ongoing access to victims’ accounts. By leveraging the Telegram API, the attackers can automatically extract chat logs, media files, and other sensitive information.

The second component, Still Audio, serves a different purpose: it enables covert audio surveillance. This implant analyzes incoming audio streams, detects speech, records conversations, and transmits these recordings to a command-and-control (C2) server. The technical sophistication of these tools highlights the evolving nature of cyber-espionage tactics employed by the Armored Likho group.

Initial Infection Method

The infection process begins with the distribution of a fake app that mimics a donation service. Although the exact distribution method remains unclear, several samples posing as legitimate applications from various Russian foundations have been identified. Once launched, the app presents a login form requesting a password, which is likely provided by the attackers. After entering a valid password, users are presented with a catalog of items available for donation, while the dropper silently decrypts and executes the payload in the background.

Technical Details of Still Sync

Still Sync operates as an asynchronous application utilizing the Tokio library for its architecture. It communicates with the C2 server via gRPC and employs FlatBuffers for message serialization. The implant collects critical system information, including motherboard serial number, CPU ID, and BIOS serial number, which it hashes and sends to the C2 server for registration.

Once registered, Still Sync can execute various commands based on settings retrieved from the server, including the ability to extract Telegram data. The module searches for the tdata folder, which contains session data, and can employ multiple methods to access this information, even bypassing standard access controls if necessary.

Capabilities of Still Audio

Still Audio mirrors the functionality of Still Sync but focuses on audio surveillance. Upon launch, it extracts a library for encoding audio data and registers with the C2 server. The implant employs a Voice Activity Detection (VAD) algorithm to determine when to start and stop recording based on audio levels. Interestingly, it does not attempt to conceal its presence, appearing in Windows settings under the name “Intel Audio.” Recorded audio is encoded and sent to the C2 server for further analysis.

Infrastructure and Victims

The infrastructure supporting this campaign is diverse, utilizing various hosting providers and domains to complicate detection efforts. The primary targets of this campaign are users in Russia, with a focus on private individuals, corporate entities, government organizations, IT companies, and educational institutions.

Conclusion

The emergence of the Still Toolkit signifies a significant evolution in the Armored Likho group’s cyber-espionage capabilities. By integrating advanced modules for data extraction and audio surveillance, the group enhances its ability to gather intelligence from compromised systems. This development underscores the need for heightened vigilance and robust security measures to counteract such sophisticated threats.

For further details on this threat and indicators of compromise, refer to the comprehensive report by Kaspersky.

Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

FQ-42 Vengeance unmanned fighter aircraft displayed at AFA 2026

The FQ-42 Vengeance unmanned fighter aircraft, developed by General Atomics, was prominently displayed at the Air, Space and Cyber conference on September 14, 2026....

Meta’s AI Assistant Muse Exposed by Zero-Day Vulnerability, Prompting Amazon to Block Access

Meta's new AI assistant, Muse, has come under scrutiny following the discovery of a zero-day vulnerability that allows locally run applications and terminal commands...

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...