Still Sync is a Rust-based espionage malware component within the Still Toolkit associated with Armored Likho, also known as Eagle Werewolf. It is designed primarily to steal Telegram Desktop session data from Windows systems and then use the stolen session material to authenticate to victims’ Telegram accounts through the Telegram API. Once authenticated, it can collect and exfiltrate account details, dialogs, private chats, groups, channels, metadata, and media files, enabling extensive surveillance of victim communications.
The malware searches for Telegram Desktop data in standard user locations as well as alternative installation paths, including Microsoft Store deployments, and can optionally broaden its search for portable installations. To access locked Telegram files, it uses backup-oriented access methods and shadow-copy style techniques, reflecting a focus on reliable collection even when files are in use. Still Sync also gathers host-identifying information such as hardware and system identifiers and derives a machine marker from them for victim tracking.
Operationally, Still Sync communicates with command infrastructure using gRPC with FlatBuffers serialization and supports both HTTP and HTTPS transport depending on configuration. It has been observed in a May 2026 cyber-espionage campaign targeting private individuals and organizations in Russia, including corporate, government, IT, and education sectors. Initial access in that campaign relied on a fake donation-themed application built with Rust and Tauri that acted as a dropper for the toolkit. Code and tradecraft overlaps link Still Sync to Armored Likho’s broader tooling ecosystem, including similarities with AquilaRAT and shared victim-identification logic. The malware’s role is intelligence collection focused on Telegram account compromise and message and media theft rather than disruptive or destructive activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API.
Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The infection chain starts with an app that mimics a donation service... In reality, the app is a dropper.
Before stealing a Telegram session, Sync searches for the tdata folder... Sync then sends a POST request with a list of files from the tdata folder...
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based stealer/spyware implant that locates and exfiltrates Telegram Desktop session data (tdata), authenticates to victim Telegram accounts, and collects user details, chats, channels, dialogs, and media files.
Rust-based stealer/spyware module that steals Telegram Desktop session data (tdata), can authenticate to the victim's Telegram account, and exfiltrate user details, chats, channels, messages, and media files. It also uses backup-privilege abuse and fallback methods to access locked files.
A Rust-based Telegram-focused stealer that locates and exfiltrates Telegram Desktop session data (tdata), authenticates to victim accounts, and collects chats, groups, channels, user details, and media files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.