Angry Likho is a cyberespionage threat actor active since at least 2023 and assessed to be part of the broader Likho cluster. Some vendors track it as Sticky Werewolf. The group shows strong tradecraft overlap with Awaken Likho and is associated with targeted intrusions against organizations in Russia and Belarus, with a particular focus on government institutions, contractors, and employees of large organizations. Angry Likho primarily relies on spearphishing with Russian-language lures and malicious attachments. Observed delivery chains have used self-extracting archives, shortcut files, heavily obfuscated command scripts, and AutoIt-based loaders to stage malware while reducing visibility. The group has demonstrated anti-analysis behavior, delayed execution, self-deletion, and process injection during payload deployment. Later activity also showed use of Base64-encoded .NET payloads concealed within image files, indicating continued evolution of its delivery methods while preserving broadly consistent tradecraft. A notable element of the group’s arsenal is Lumma, an infostealer used to harvest credentials and other sensitive data. In observed campaigns, the malware targeted browser data, cookies, usernames, passwords, financial information, cryptocurrency-wallet data, authenticator data, remote-access software artifacts, and password-manager content. This indicates that Angry Likho’s operations combine espionage-oriented victim selection with credential theft and broad information collection from compromised endpoints. The actor is characterized by relatively compact infrastructure and a limited but reusable implant set. Attribution to Angry Likho is supported by recurring Russian-language bait themes, overlapping loader structure, similarly obfuscated scripts, and continuity with previously documented Likho-associated activity. Known aliases and related naming include Sticky Werewolf, and the group is commonly discussed alongside other Likho-cluster designations such as Awaken Likho.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
56 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage-focused APT group active against Russian organizations.
Referenced as a prominent threat actor group that has used the Lumma infostealer.
Targeted spear-phishing campaign against employees of large organizations, especially Russian government institutions and contractors, using self-extracting archives, obfuscated AutoIt-based implants, and Lumma stealer to steal credentials, banking data, and cryptowallet information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.