Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The May 2026 Armored Likho campaign introduced a new Rust-based espionage suite called Still Toolkit, consisting of Still Sync and Still Audio. Still Sync stole Telegram Desktop session data and exfiltrated chats and media via the Telegram API, while Still Audio covertly recorded microphone audio when speech was detected.
In May 2026, a new cyber-espionage campaign attributed with high confidence to Armored Likho targeted private users and organizations in Russia, including corporate, government, IT, and education sectors. The attackers used fake charity-assistance applications themed around several foundations as the initial lure.
In February 2026, Eagle Werewolf used a compromised UAV-themed Telegram channel and support account to distribute a ZIP archive containing a Rust/Tauri dropper disguised as part of a fake Starlink activation process. The dropper decrypted and launched a Go payload and registered infected machines with command-and-control infrastructure.
Researchers identified Eagle Werewolf as a distinct cluster after linking espionage activity detected in February 2026 to earlier campaigns. Positive Technologies and BI.ZONE described this as the basis for separating the cluster from related 'werewolf' activity.
BI.ZONE reported that the Eagle Werewolf cluster had been active since at least May 2023. The group was assessed to target government and industrial organizations as well as people connected to UAV production and engineering.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 62 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourcebi.zone
Open sourcebi.zone
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.