Threat Advisory

Armored Likho APT Impacts Telegram Credentials for Cyber Espionage Activities

Threat: Malware Campaign
Threat Actor Name: Armored Likho
Targeted Region: Russia
Alias: Eagle Werewolf
Targeted Sector: Technology & IT, Government & Defense, Education
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Armored Likho has expanded its cyber-espionage capabilities using the Still Toolkit, a framework designed to compromise targeted systems and maintain covert access. The threat actor has been observed targeting government entities, critical infrastructure organizations, and other high-value victims by combining phishing-based delivery methods with modular malware components. The campaign demonstrates an ongoing evolution of Armored Likhos operational capabilities, focusing on stealth, persistence, and sensitive data collection.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Armored Likho has expanded its cyber-espionage capabilities using the Still Toolkit, a framework designed to compromise targeted systems and maintain covert access. The threat actor has been observed targeting government entities, critical infrastructure organizations, and other high-value victims by combining phishing-based delivery methods with modular malware components. The campaign demonstrates an ongoing evolution of Armored Likhos operational capabilities, focusing on stealth, persistence, and sensitive data collection.[emaillocker id="1283"]

The attack chain begins with spear-phishing emails containing malicious archives, shortcuts, or executable files disguised as legitimate documents. Once executed, the malware deploys additional components that establish persistence and communicate with command-and-control infrastructure. The Still Toolkit includes capabilities for credential theft, information harvesting, system surveillance, and remote access, enabling operators to collect browser data, messaging application information, files, screenshots, and other sensitive artifacts. The toolkit also incorporates evasion techniques to reduce detection, including obfuscated code execution and modular payload delivery mechanisms that allow attackers to adapt functionality based on victim environments.

It highlights Armored Likho continued development of its cyber espionage capabilities and its focus on maintaining stealthy access to targeted environments. Organizations should strengthen phishing defenses, monitor suspicious script and shortcut executions, implement endpoint detection controls, and continuously monitor outbound communications to identify potential compromise attempts associated with this threat activity.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.006 Command and Scripting Interpreter Python
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
T1113 Screen Capture -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

 

MBC MAPPING:

Objective Behaviour ID Behaviour
Command and Control B0030 C2 Communication
Discovery E1083 File and Directory Discovery
E1082 System Information Discovery
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder

 

REFERENCES:

The following reports contain further technical details:

https://securelist.com/armored-likho-still-toolkit/121033/

[/emaillocker]
crossmenu