EXECUTIVE SUMMARY:
Armored Likho has expanded its cyber-espionage capabilities using the Still Toolkit, a framework designed to compromise targeted systems and maintain covert access. The threat actor has been observed targeting government entities, critical infrastructure organizations, and other high-value victims by combining phishing-based delivery methods with modular malware components. The campaign demonstrates an ongoing evolution of Armored Likhos operational capabilities, focusing on stealth, persistence, and sensitive data collection.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Armored Likho has expanded its cyber-espionage capabilities using the Still Toolkit, a framework designed to compromise targeted systems and maintain covert access. The threat actor has been observed targeting government entities, critical infrastructure organizations, and other high-value victims by combining phishing-based delivery methods with modular malware components. The campaign demonstrates an ongoing evolution of Armored Likhos operational capabilities, focusing on stealth, persistence, and sensitive data collection.[emaillocker id="1283"]
The attack chain begins with spear-phishing emails containing malicious archives, shortcuts, or executable files disguised as legitimate documents. Once executed, the malware deploys additional components that establish persistence and communicate with command-and-control infrastructure. The Still Toolkit includes capabilities for credential theft, information harvesting, system surveillance, and remote access, enabling operators to collect browser data, messaging application information, files, screenshots, and other sensitive artifacts. The toolkit also incorporates evasion techniques to reduce detection, including obfuscated code execution and modular payload delivery mechanisms that allow attackers to adapt functionality based on victim environments.
It highlights Armored Likho continued development of its cyber espionage capabilities and its focus on maintaining stealthy access to targeted environments. Organizations should strengthen phishing defenses, monitor suspicious script and shortcut executions, implement endpoint detection controls, and continuously monitor outbound communications to identify potential compromise attempts associated with this threat activity.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| T1113 | Screen Capture | - | |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
MBC MAPPING:
| Objective | Behaviour ID | Behaviour |
| Command and Control | B0030 | C2 Communication |
| Discovery | E1083 | File and Directory Discovery |
| E1082 | System Information Discovery | |
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]