CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations

Cybersecurity News Archived Aug 13, 2026 ✓ Full text saved

A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia. Once opened, the fake application quietly installs tools designed to take over Telegram accounts and capture private conversations. The campaign matters because it combines account access with microphone surveillance. A compromised person can lose chat […] The post Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations appeared first

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations By Tushar Subhra Dutta August 13, 2026 A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia. Once opened, the fake application quietly installs tools designed to take over Telegram accounts and capture private conversations. The campaign matters because it combines account access with microphone surveillance. A compromised person can lose chat histories, files, contacts, and spoken discussions in one incident, creating serious privacy and business risks. Unlike a conventional steal-and-leave operation, it gives operators a way to watch a target’s communications over time and build a more complete picture of personal or organizational activity. That persistence can multiply the harm, especially for staff with access to sensitive projects, customer data, or internal decision-making across affected public and private organizations. Securelist said in a report shared with Cyber Security News (CSN) that it discovered the campaign in May 2026. The login form (Source – Securelist) Its researchers identified the new Rust-based Still Toolkit while examining activity against private individuals, companies, government bodies, IT firms, and education organizations in Russia. The initial delivery route remains unclear, but the lure is familiar. Victims receive software posing as a service for charitable donations, then see a password screen and a catalog of items that makes the program appear genuine while the hidden payload starts in the background. Armored Likho The toolkit’s first component, Still Sync, looks for Telegram Desktop session data. That information can allow an attacker to resume an already authenticated account, a danger illustrated by the risks of cloned Telegram sessions, without having to know the victim’s ordinary login credentials. After it gains access, Sync can use Telegram’s application interface to collect account details, private chats, groups, channels, and media files smaller than 250MB. Example Still Sync logs (Source – Securelist) It can also gather names, phone numbers, membership details, documents, stickers, photos, and contacts, turning one endpoint infection into a broad intelligence haul. The malware first registers the infected device with its command server and waits for settings that switch on its collection features. It searches normal and portable Telegram locations, and can attempt backup-based methods if standard file access fails, making a missing file permission prompt a poor sign of safety. This approach is distinct from password phishing. It abuses local proof that a user has already signed in, which is why recent Telegram authentication phishing and session theft demand attention even when two-step verification is enabled. A separate desktop passcode can add protection to locally stored Telegram data. Audio Module Extends Surveillance Still Audio adds a second layer of spying by monitoring an available microphone for speech. When sound crosses a set threshold, it begins recording, keeps a small buffer so the start is not missed, converts the audio to MP3, and sends it to the operator’s infrastructure. The module can run in the background as a Windows service, yet researchers found that it did not fully conceal microphone use. In the examined sample, the program appeared in Windows microphone settings under a name resembling a legitimate audio component, an important clue during incident response. Its fallback design also lets the operators change server addresses if a primary connection is unavailable for three days. That resilience resembles ClickFix malware delivery chains, where modular threats fetch new functions or replacement infrastructure instead of relying on a single fixed server. The malicious module in the list of apps using the microphone (Source – Securelist) Researchers linked the campaign to Armored Likho, also called Eagle Werewolf, through code and infrastructure similarities with earlier operations. The group’s move to a combined toolkit reflects a wider trend seen in Rust malware surveillance campaigns: compact modules can collect several forms of sensitive data after one deceptive click. People who installed a suspicious donation app should disconnect the device from networks, preserve evidence, and have a trusted security team examine it. From a clean device, they should review Telegram’s active sessions, terminate unfamiliar ones, reset relevant passwords, and consider the chats and recordings exposed. Organizations should block the indicators below, hunt for related activity, and notify affected users promptly. Indicators of compromise (IoCs):- Type Indicator Description SHA-256 C1D1EE16B92E6A138FFA048855F75D7D17674B250D8B422A50A86C9FF207186D Reported malware sample hash SHA-256 62801F6223E860A7CCA271522E303B2D68F0365D2FA8C828D012D8859E52A773 Reported malware sample hash SHA-256 4BD7C352AE277B0E38D07BEEDD4DD507D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD Reported malware sample hash SHA-256 2CA8ADBAB98EBE305EACF272CF48F5A03AC41B097236A7723821848AE31EF141 Reported malware sample hash File hash 439255736797BC88BD19F282449E0436 Reported malware sample hash Domain / IP address orderapiserver[.]info / 187.127.153[.]38 Donation-app content infrastructure Domain / IP address tg4service[.]com / 159.198.37[.]74 Still Sync command-and-control infrastructure Domain / IP address srwinservice[.]com / 213.252.244[.]123 Still Audio command-and-control infrastructure Domain / IP address screenserv[.]com / 23.26.237[.]250 Campaign infrastructure Domain / IP address windowserv[.]net / 23.27.24[.]30 Campaign infrastructure Domain / IP address managementapiservice[.]com / 188.212.124[.]178 Campaign infrastructure Domain / IP address service8date[.]com / 145.223.69[.]143 Campaign infrastructure Domain / IP address updateservs[.]com / 145.223.68[.]66 Campaign infrastructure URL hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json Dead-drop resolver location used to retrieve an encrypted command-server address File name IntAudio.exe Observed Still Audio sample name File name libmp3lame.dll Audio-encoding library extracted by Still Audio File name logfile.log Still Audio logging artifact File name bin Hidden Still Sync error-log artifact Service name TReload Still Sync background service Service name auxhost Still Audio background service  Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world Tags cyber security cyber security news Copy URL Linkedin Twitter ReddIt Telegram Tushar Subhra Dutta Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security News Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks Cyber Security Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers Cyber Security News North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees Cyber Security News CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks Cyber Security News GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗