Librarian Likho is a named cluster within the Likho grouping of threat activity associated with cyberespionage-focused operations. It is referenced alongside related clusters such as Awaken Likho, Angry Likho, Mythic Likho, and other espionage-oriented actors active against Russian and CIS organizations. Available information directly supports its classification as part of an espionage-focused threat landscape, but specific tradecraft, malware families, victimology, and operational details for Librarian Likho itself are not currently available from the supplied facts. The broader context in which it appears indicates sustained targeting of government, telecommunications, energy, defense, and industrial entities by multiple advanced groups using spearphishing, valid-account abuse, cloud-based command-and-control, and living-off-the-land techniques, but those behaviors are not individually attributable to Librarian Likho at high confidence here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.