All incidents

Armored Likho espionage campaign targets Russian Telegram users

campaignopenAug 13, 2026 — Aug 19, 2026
Armored Likho's fake donation apps spy on Russian Telegram users

ARMORED Likho, a cyber‑espionage group also tracked as Eagle Werewolf, has been distributing fake donation applications that covertly harvest Telegram session data and record ambient audio on Russian users’ devices according to recent analysis. The campaign, first observed in May 2026, tricks victims into installing the apps under the guise of charitable contributions.

The malicious payload is the Still Toolkit, which consists of two main modules as described by Kaspersky. Still Sync extracts the Telegram session files stored on the device, allowing attackers to reconstruct chat logs and media files without needing the victim’s password. Still Audio activates the microphone silently and uploads recordings to a command‑and‑control server.

Because the stolen session data includes the authentication tokens, the attackers can bypass two‑factor authentication and access the account as if they were the legitimate user. The toolkit does not rely on a known vulnerability, so no CVE identifier has been assigned to the activity.

Kaspersky researchers linked the activity to Armored Likho after observing the group’s reuse of earlier infrastructure and coding patterns in their report. Targets include private individuals as well as employees in the IT and education sectors, suggesting a focus on gathering both personal and proprietary information. The campaign remains active, with recent samples seen as late as mid‑August 2026.

Organisations should review application installation logs for any apps sourced from unofficial stores or side‑loaded packages. Endpoint monitoring tools can flag the creation of unusual processes such as hidden audio recording services or unexpected access to Telegram’s data directories. User training is essential; staff must be warned to verify the legitimacy of any donation app before granting permissions.

Keeping mobile operating systems and applications up to date reduces the risk of exploitation through known flaws, even though this specific toolkit does not depend on a public CVE. Network traffic analysis can help detect exfiltration attempts to unfamiliar domains, prompting a quicker response.

Intelligence briefing updated Aug 19, 2026

Armored Likho
Root sourcesecurelist.com
Timeline Coverage

Swipe to explore timeline