logo

Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia

ID: 08ec68f8-5b5a-5218-8042-6ad6638898e3

STIX ID: report--08ec68f8-5b5a-5218-8042-6ad6638898e3

Feed Name: HackRead

Threat Score
75/100

Date Published: 2025-02-27

Date Updated: 2026-04-22

Author: Waqas

...
...

Angry Likho APT (aka Sticky Werewolf) has resurfaced with targeted spear-phishing campaigns against Russian and Belarusian government agencies and contractors, using malicious RAR attachments and a self-extracting installer (FrameworkSurvivor.exe) that launches Helping.cmd and an AutoIt loader to deploy the Lumma stealer; researchers observed image-based Base64 payloads, expanded command servers, and over 60 malicious implants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.