Armored Likho expands its cyber-espionage toolkit
ID: fa818159-2d31-55bf-86a2-c8e8b18f5299
STIX ID: report--fa818159-2d31-55bf-86a2-c8e8b18f5299
Feed Name: Securelist by Kaspersky
In May 2026, researchers uncovered an Armored Likho cyber-espionage campaign targeting Russian individuals and organizations that uses Tauri-based fake donation apps to drop a Rust "Still Toolkit": Still Sync (Telegram session/data stealer) and Still Audio (voice-activated eavesdropper); the report documents the infection chain, technical implementation, C2 and dead-drop resolver mechanisms, victimology, infrastructure, attribution, and provides file hashes and domain IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
