Still Toolkit is a Rust-based cyber-espionage malware toolkit associated with the Armored Likho threat group, also known as Eagle Werewolf. It was used in campaigns targeting private individuals as well as government, corporate, IT, and education organizations in Russia. The toolkit has been observed delivered by a Rust and Tauri-based dropper masquerading as a charitable aid or donation application, although the broader distribution chain is not fully established.
The toolkit comprises at least two components: Still Sync and Still Audio. Still Sync is designed to steal Telegram Desktop session data from local storage, enabling operators to authenticate to an already logged-in victim account without needing the victim’s Telegram password. Using the hijacked session, operators can collect account details, chats, groups, channels, participant information, contacts, and media. The component searches standard and nonstandard Telegram locations, including portable and Microsoft Store installations, and can use backup-oriented file access methods and elevated backup privileges to obtain locked files.
Still Audio is an implant for covert microphone surveillance. It enumerates audio input devices, monitors microphone input for speech, records when voice activity is detected, buffers audio to avoid missing the start of speech, encodes recordings as MP3, and exfiltrates them to attacker-controlled infrastructure. It can run persistently as a background service and includes fallback command-and-control recovery logic using an alternate resolver mechanism.
The toolkit’s architecture and tradecraft indicate a modular, long-term intelligence-collection capability focused on multi-channel surveillance and data theft. Attribution to Armored Likho is supported by code and architectural overlaps, shared encryption methods, infrastructure similarities, and links to earlier tooling such as AquilaRAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
В арсенале группировки появился новый набор малвари Still Toolkit, который позволяет похищать данные из Telegram и вести скрытую прослушку через микрофон зараженного устройства.
В арсенале группировки появился новый набор малвари Still Toolkit, который позволяет похищать данные из Telegram и вести скрытую прослушку через микрофон зараженного устройства.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure.
The algorithms match down to the PowerShell commands used to collect system information.
Приложение ... выглядит настоящим: после запуска оно просит ввести пароль ... а затем отображает каталог товаров ... Пока жертва изучает ассортимент, дроппер расшифровывает и запускает вредоносный пейлоад.
После запуска отображается форма авторизации... Пока пользователь просматривает товары, дроппер незаметно выполняет расшифровку и запуск полезной нагрузки для следующего этапа. | В качестве приманки злоумышленники использовали поддельное приложение, имитирующее сервис для отправки материальной помощи... Приложение на самом деле является дроппером.
The infection chain starts with an app that mimics a donation service... In reality, the app is a dropper.
Still Sync проверяет стандартные каталоги Telegram, версию из Microsoft Store и, при соответствующей настройке, весь диск C:\.
Still Audio, предназначен для аудиошпионажа. Малварь анализирует сигнал, поступающий с микрофона зараженного устройства, и начинает запись только в случае обнаружения речи.
After it gains access, Sync can use Telegram’s application interface to collect account details, private chats, groups, channels, and media files smaller than 250MB. It can also gather names, phone numbers, membership details, documents, stickers, photos, and contacts...
Still Audio способен получать резервный адрес управляющего сервера с GitHub, если основной C2 недоступен несколько дней.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware toolkit used for cyber-espionage. It consists of Still Sync, which steals Telegram Desktop tdata/session files to access chats, participants, and media via the Telegram API, and Still Audio, which performs microphone-based audio surveillance, recording speech and sending MP3 files to attacker-controlled servers.
A Rust-based espionage toolkit used in a fake donation app campaign. It steals Telegram session data and account contents, and includes audio surveillance capabilities for persistent monitoring of victims.
A Rust-based cyber-espionage toolkit used by Armored Likho that includes modules for Telegram session theft, chat/media collection, and covert audio surveillance.
Rust-based cyber-espionage toolkit used by Armored Likho. It includes modules for stealing Telegram session data, accessing Telegram accounts via the Telegram API to exfiltrate chats and media, and covert audio surveillance via microphone recording and exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.