securelist.com 8/13/2026, 8:51:07 AM · external

Armored Likho uses Still Toolkit to spy on Telegram in Russia

Armored Likho uses Still Toolkit to spy on Telegram in Russia
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

IN May 2026, Kaspersky researchers uncovered a new cyber-espionage campaign by the Armored Likho group targeting individuals and organizations in Russia. The campaign utilizes a deceptive app to deliver the **Still Toolkit**, which comprises two primary components: **Still Sync** and **Still Audio**.

**Still Sync** steals Telegram session data, enabling attackers to access chat logs and media files, while **Still Audio** performs covert audio surveillance by recording conversations. The attackers expand their arsenal through new tools while maintaining techniques from previous campaigns, indicating an intent to enhance information-gathering capabilities. Key targets include private individuals and sectors such as IT and education, indicating a sophisticated level of cyber-espionage.

Kaspersky products identify these threats as `Trojan.Win64.Agent.*` and `HEUR:Backdoor.Win32.Generic`. Overall, the campaign demonstrates significant evolution in the attackers' toolkit and methods.

View full article

Article by CyberSIXT