Armored Likho expands its cyber-espionage toolkit (opens in a new tab)
Why readDetails a new Rust implant set, the Still Toolkit, whose Still Sync component steals Telegram session data so operators can pull chats and media through the API afterwards.
Kaspersky found a May 2026 espionage campaign by Armored Likho (also tracked as Eagle Werewolf) against Russian corporations, public sector, IT and education, using a fake donation-service app as the lure. The notable part is the payload rather than the delivery: a Rust-written toolkit whose Still Sync module exfiltrates Telegram session material, giving the attacker continuing API-level access to the victim's account and its chat logs and files. The tradecraft lines up more closely with the group's February activity than with its most recent reported attacks, and the arsenal has grown substantially.
Indicators4
- URLs
hxxps://tg4service[.]com:443hxxps://srwinservice[.]com- Domains
orderapiserver[.]infotg4service[.]com