IN May 2026, Kaspersky researchers uncovered a new cyber-espionage campaign by the Armored Likho group targeting individuals and organizations in Russia. The campaign utilizes a deceptive app to deliver the **Still Toolkit**, which comprises two primary components: **Still Sync** and **Still Audio**.
**Still Sync** steals Telegram session data, enabling attackers to access chat logs and media files, while **Still Audio** performs covert audio surveillance by recording conversations. The attackers expand their arsenal through new tools while maintaining techniques from previous campaigns, indicating an intent to enhance information-gathering capabilities. Key targets include private individuals and sectors such as IT and education, indicating a sophisticated level of cyber-espionage.
Kaspersky products identify these threats as `Trojan.Win64.Agent.*` and `HEUR:Backdoor.Win32.Generic`. Overall, the campaign demonstrates significant evolution in the attackers' toolkit and methods.