Still Toolkit is a Rust-based cyber-espionage malware toolkit associated with Armored Likho, also known as Eagle Werewolf. It has been used in campaigns targeting private individuals and organizations in Russia, including corporate, government, information technology, and education environments. The toolkit is modular and includes at least two components: Still Sync and Still Audio.
Still Sync is designed to steal Telegram Desktop session data and use that material to authenticate to victims’ Telegram accounts through the Telegram API. It can collect account details, dialogs, chat metadata, messages, groups, channels, and media, enabling large-scale intelligence collection from compromised Telegram accounts. It also gathers host-identifying system information and can search both standard and nonstandard locations for Telegram data. To access locked files, it can abuse backup-related mechanisms and shadow-copy-based access methods.
Still Audio is an audio-surveillance implant for covert microphone monitoring. It enumerates audio input devices, performs voice-activity-based recording, encodes captured audio, and uploads recordings to attacker-controlled infrastructure. It can operate as a background service and includes fallback command-and-control recovery logic using an external dead-drop mechanism, reflecting an emphasis on resilience and long-term collection.
The toolkit has been linked to fake donation-themed applications used as droppers. In observed operations, a Rust and Tauri-based lure application presented benign-looking content while decrypting and launching the espionage payload in the background. Code-level and tradecraft overlaps connect Still Toolkit to earlier Armored Likho activity, including similarities with AquilaRAT in host-identification logic, encryption usage, and command-and-control recovery design.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data... The second component, Still Audio, is an implant for covert audio surveillance.
During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data... The second component, Still Audio, is an implant for covert audio surveillance.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based cyber-espionage toolkit used by Armored Likho that includes modules for Telegram session theft, chat/media collection, and covert audio surveillance.
Rust-based cyber-espionage toolkit used by Armored Likho. It includes modules for stealing Telegram session data, accessing Telegram accounts via the Telegram API to exfiltrate chats and media, and covert audio surveillance via microphone recording and exfiltration.
A Rust-based cyber-espionage toolkit used by Armored Likho consisting of modules for Telegram session theft/data exfiltration and covert audio surveillance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.