Still Audio is a Rust-based audio surveillance implant associated with the Still Toolkit espionage framework and attributed with high confidence to the Armored Likho threat actor, also known as Eagle Werewolf. It is designed for covert microphone monitoring on Windows systems and supports long-term intelligence collection by detecting speech activity, recording audio when configured thresholds are met, encoding the captured sound as MP3, and exfiltrating the recordings to attacker-controlled infrastructure. The implant maintains a small pre-buffer so the beginning of speech is not missed and can enumerate available audio input devices for operator tasking. Still Audio can run persistently in the background as a Windows service and includes fallback command-and-control recovery logic, including alternate server selection and a dead-drop resolver mechanism that retrieves encrypted configuration data when primary communications are unavailable for an extended period. It has been deployed in a broader cyber-espionage campaign targeting private individuals and organizations in Russia, including corporate, government, IT, and educational sectors, using fake donation-themed applications as the lure for initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Still Audio adds a second layer of spying by monitoring an available microphone for speech.
Still Audio adds a second layer of spying by monitoring an available microphone for speech.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Still Audio способен получать резервный адрес управляющего сервера с GitHub, если основной C2 недоступен несколько дней.
It talks to the server over gRPC... It supports both HTTP and HTTPS as transport protocols... sends it in a POST request to /still.rpc.Sync/RegisterMachine.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A surveillance module within Still Toolkit that monitors microphone input, records speech when a threshold is crossed, converts recordings to MP3, and exfiltrates them to attacker infrastructure. It can run as a Windows service and supports fallback C2 changes.
A Rust-based audio surveillance implant that captures microphone input, uses RMS-based voice activity detection to record speech, encodes recordings as MP3, and uploads them to command-and-control infrastructure.
Rust-based audio surveillance implant that monitors microphone input, detects speech using an RMS/VAD-like threshold, records conversations, encodes them with libmp3lame, and uploads recordings to C2. It also supports dead-drop resolution via GitHub to recover C2 addresses.
A Rust-based audio surveillance implant that captures microphone input, detects speech using RMS/VAD-style logic, records conversations, encodes them with libmp3lame, and uploads recordings to C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.