Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia. Once opened, the fake application quietly installs tools designed to take over Telegram accounts and capture private conversations. The campaign matters because it combines account access with microphone surveillance. A compromised person can lose chat […] The post Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations appeared first
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
By Tushar Subhra Dutta
August 13, 2026
A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia.
Once opened, the fake application quietly installs tools designed to take over Telegram accounts and capture private conversations.
The campaign matters because it combines account access with microphone surveillance.
A compromised person can lose chat histories, files, contacts, and spoken discussions in one incident, creating serious privacy and business risks.
Unlike a conventional steal-and-leave operation, it gives operators a way to watch a target’s communications over time and build a more complete picture of personal or organizational activity.
That persistence can multiply the harm, especially for staff with access to sensitive projects, customer data, or internal decision-making across affected public and private organizations.
Securelist said in a report shared with Cyber Security News (CSN) that it discovered the campaign in May 2026.
The login form (Source – Securelist)
Its researchers identified the new Rust-based Still Toolkit while examining activity against private individuals, companies, government bodies, IT firms, and education organizations in Russia.
The initial delivery route remains unclear, but the lure is familiar. Victims receive software posing as a service for charitable donations, then see a password screen and a catalog of items that makes the program appear genuine while the hidden payload starts in the background.
Armored Likho
The toolkit’s first component, Still Sync, looks for Telegram Desktop session data.
That information can allow an attacker to resume an already authenticated account, a danger illustrated by the risks of cloned Telegram sessions, without having to know the victim’s ordinary login credentials.
After it gains access, Sync can use Telegram’s application interface to collect account details, private chats, groups, channels, and media files smaller than 250MB.
Example Still Sync logs (Source – Securelist)
It can also gather names, phone numbers, membership details, documents, stickers, photos, and contacts, turning one endpoint infection into a broad intelligence haul.
The malware first registers the infected device with its command server and waits for settings that switch on its collection features.
It searches normal and portable Telegram locations, and can attempt backup-based methods if standard file access fails, making a missing file permission prompt a poor sign of safety.
This approach is distinct from password phishing. It abuses local proof that a user has already signed in, which is why recent Telegram authentication phishing and session theft demand attention even when two-step verification is enabled.
A separate desktop passcode can add protection to locally stored Telegram data.
Audio Module Extends Surveillance
Still Audio adds a second layer of spying by monitoring an available microphone for speech.
When sound crosses a set threshold, it begins recording, keeps a small buffer so the start is not missed, converts the audio to MP3, and sends it to the operator’s infrastructure.
The module can run in the background as a Windows service, yet researchers found that it did not fully conceal microphone use.
In the examined sample, the program appeared in Windows microphone settings under a name resembling a legitimate audio component, an important clue during incident response.
Its fallback design also lets the operators change server addresses if a primary connection is unavailable for three days.
That resilience resembles ClickFix malware delivery chains, where modular threats fetch new functions or replacement infrastructure instead of relying on a single fixed server.
The malicious module in the list of apps using the microphone (Source – Securelist)
Researchers linked the campaign to Armored Likho, also called Eagle Werewolf, through code and infrastructure similarities with earlier operations.
The group’s move to a combined toolkit reflects a wider trend seen in Rust malware surveillance campaigns: compact modules can collect several forms of sensitive data after one deceptive click.
People who installed a suspicious donation app should disconnect the device from networks, preserve evidence, and have a trusted security team examine it.
From a clean device, they should review Telegram’s active sessions, terminate unfamiliar ones, reset relevant passwords, and consider the chats and recordings exposed.
Organizations should block the indicators below, hunt for related activity, and notify affected users promptly.
Indicators of compromise (IoCs):-
Type Indicator Description
SHA-256 C1D1EE16B92E6A138FFA048855F75D7D17674B250D8B422A50A86C9FF207186D Reported malware sample hash
SHA-256 62801F6223E860A7CCA271522E303B2D68F0365D2FA8C828D012D8859E52A773 Reported malware sample hash
SHA-256 4BD7C352AE277B0E38D07BEEDD4DD507D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD Reported malware sample hash
SHA-256 2CA8ADBAB98EBE305EACF272CF48F5A03AC41B097236A7723821848AE31EF141 Reported malware sample hash
File hash 439255736797BC88BD19F282449E0436 Reported malware sample hash
Domain / IP address orderapiserver[.]info / 187.127.153[.]38 Donation-app content infrastructure
Domain / IP address tg4service[.]com / 159.198.37[.]74 Still Sync command-and-control infrastructure
Domain / IP address srwinservice[.]com / 213.252.244[.]123 Still Audio command-and-control infrastructure
Domain / IP address screenserv[.]com / 23.26.237[.]250 Campaign infrastructure
Domain / IP address windowserv[.]net / 23.27.24[.]30 Campaign infrastructure
Domain / IP address managementapiservice[.]com / 188.212.124[.]178 Campaign infrastructure
Domain / IP address service8date[.]com / 145.223.69[.]143 Campaign infrastructure
Domain / IP address updateservs[.]com / 145.223.68[.]66 Campaign infrastructure
URL hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json Dead-drop resolver location used to retrieve an encrypted command-server address
File name IntAudio.exe Observed Still Audio sample name
File name libmp3lame.dll Audio-encoding library extracted by Still Audio
File name logfile.log Still Audio logging artifact
File name bin Hidden Still Sync error-log artifact
Service name TReload Still Sync background service
Service name auxhost Still Audio background service
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks
Cyber Security
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Cyber Security News
North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
Cyber Security News
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
Cyber Security News
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?