Summary Points
- The Armored Likho group has expanded its toolkit with new Rust-based modules, Still Sync and Still Audio, enabling ongoing Telegram account access and covert audio surveillance.
- Infection begins via malicious Rust dropper apps mimicking donation services, which deploy implants capable of exfiltrating messaging data and hijacking communication channels.
- The campaign poses a significant espionage threat to Russian individuals and organizations across sectors, leveraging prolonged, multi-channel data collection for intelligence gathering.
Threat, Attack Techniques, and Targets
In May 2026, researchers identified a new cyber-espionage campaign by the Armored Likho group. They target private individuals and organizations across Russia. These targets include large companies, government bodies, IT firms, and educational institutions. The attackers use a fake app, pretending to be a donation service, to infect victims. The app is built with Rust and uses the Tauri framework. It displays a login form asking for a password. When the user enters the password, the app shows a catalog. While the user browses, the malware decrypts and launches the next payload. The campaign introduces a new toolkit called Still, composed of Still Sync and Still Audio. Still Sync steals Telegram session data and allows ongoing access to messages and media. Still Audio captures conversations through microphone surveillance. Both tools communicate with command-and-control servers via web requests and operate in background services.
Impact, Security Implications, and Remediation Guidance
This campaign’s impact is significant. Attackers can steal Telegram chats, media, and conduct secret audio recording. Victims’ sensitive personal and organizational data are at risk. The malware’s ability to maintain access and gather extensive information increases the threat level. The use of covert audio surveillance raises privacy concerns and complicates detection. For security, organizations should monitor for suspicious app behavior and unusual network activity. They should also check for the presence of malicious tools like Still Sync and Still Audio. Because detailed remediation guidance is not provided here, affected parties should consult with the relevant security vendors or authorities. It is essential to obtain expert advice tailored to specific environments to remove the malware and strengthen defenses.
Stay Ahead with the Latest Tech Trends
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
