Still Sync is a Rust-based espionage stealer associated with the Still Toolkit and attributed with high confidence to the Armored Likho threat actor, also known as Eagle Werewolf. It targets Telegram Desktop on Windows systems by locating and extracting local session artifacts, allowing operators to hijack already authenticated Telegram accounts without needing the victim’s password. Using the stolen session data, the malware can authenticate through the Telegram API and collect account details, dialogs, private chats, groups, channels, contacts, and media files, enabling broad intelligence collection from victim communications.
The malware is designed for covert post-compromise collection. It registers infected hosts with command-and-control infrastructure, retrieves configuration, and gathers host-identifying information to generate a unique machine marker. It searches standard, Microsoft Store, and portable Telegram Desktop locations, and can use backup-oriented file access methods to obtain locked Telegram data when normal access fails. Reported collection includes chat metadata, membership information, documents, photos, stickers, contacts, and media below a configured size threshold.
Still Sync has been observed in a 2026 cyber-espionage campaign targeting private individuals and organizations in Russia, including corporate, government, IT, and education sectors. Delivery in that campaign relied on a fake charitable-donation themed application that acted as a dropper for the broader Still Toolkit. Tradecraft and code-level overlaps link the malware to earlier Armored Likho operations, including similarities in host-identification logic and broader tooling architecture. Still Sync is best characterized as a Telegram-focused infostealer used for surveillance and data exfiltration in targeted espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The toolkit’s first component, Still Sync, looks for Telegram Desktop session data.
The toolkit’s first component, Still Sync, looks for Telegram Desktop session data.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The infection chain starts with an app that mimics a donation service... In reality, the app is a dropper.
Still Sync проверяет стандартные каталоги Telegram, версию из Microsoft Store и, при соответствующей настройке, весь диск C:\.
Используя похищенные данные, злоумышленники могут через Telegram API автоматически выгружать из аккаунта переписку, медиафайлы и другую информацию.
After it gains access, Sync can use Telegram’s application interface to collect account details, private chats, groups, channels, and media files smaller than 250MB. It can also gather names, phone numbers, membership details, documents, stickers, photos, and contacts...
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A component of Still Toolkit that searches for Telegram Desktop session artifacts, registers the infected device with a command server, and uses Telegram’s API to collect account details, chats, groups, channels, media, contacts, and related metadata.
A Rust-based stealer/spyware implant that locates and exfiltrates Telegram Desktop session data (tdata), authenticates to victim Telegram accounts, and collects user details, chats, channels, dialogs, and media files.
Rust-based stealer/spyware module that steals Telegram Desktop session data (tdata), can authenticate to the victim's Telegram account, and exfiltrate user details, chats, channels, messages, and media files. It also uses backup-privilege abuse and fallback methods to access locked files.
A Rust-based Telegram-focused stealer that locates and exfiltrates Telegram Desktop session data (tdata), authenticates to victim accounts, and collects chats, groups, channels, user details, and media files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.