The cyber-espionage group known as 'Armored Likho' (or Eagle Werewolf) has been observed deploying a new and sophisticated espionage toolset in a campaign targeting entities within Russia. Research published by Kaspersky on August 13, 2026, details the new malware suite, written in Rust and dubbed the 'Still Toolkit'. This toolkit is highly specialized for intelligence gathering, featuring components designed to hijack Telegram accounts by stealing session data and to conduct covert audio surveillance by recording conversations via the victim's microphone. The campaign, active since May 2026, continues the group's pattern of using socially-engineered lures, in this case themed around fundraising, to entice targets into executing the malware.
The 'Still Toolkit' is the primary innovation in this campaign and consists of two main components:
'Still Sync': This component is a specialized information stealer focused on Telegram. It is designed to locate and exfiltrate Telegram session data from the victim's machine. By stealing these session files (T1555), the attackers can effectively hijack the victim's account. They can then use the Telegram API to access the account from their own infrastructure, allowing them to download chat histories, media files, and monitor communications in real-time without needing the victim's password.
'Still Audio': This component is an audio surveillance implant. It accesses the device's microphone and actively listens for human speech. When speech is detected, it begins recording the audio, compresses it, and exfiltrates the recording to a command-and-control (C2) server. This provides the attackers with the ability to eavesdrop on sensitive conversations occurring near the compromised device (T1123).
The malware is written in Rust, a programming language increasingly favored by malware authors for its performance and difficulty to reverse engineer. While the C2 infrastructure for this campaign does not directly overlap with past Armored Likho operations, Kaspersky notes similarities in hosting providers and domain naming conventions, and attributes the activity to the group with high confidence based on code-level overlaps with previous malware families.
The deployment of the 'Still Toolkit' represents a significant evolution in Armored Likho's capabilities. The targeted theft of Telegram sessions allows for deep and persistent intelligence gathering from a platform widely used for both personal and business communication in the region. The addition of an audio surveillance module demonstrates the group's intent to gather intelligence from not only the digital realm but also the physical environment of their targets. For the affected individuals and organizations in Russia, this poses a severe threat of espionage, potentially leading to the compromise of sensitive government, corporate, and personal information.
No specific IOCs were provided in the source articles.
Security teams can hunt for signs of this activity by looking for:
*\tdata, *\Telegram Desktopstill_sync.exe, still_audio.exeapi.telegram.orgTelegram.exe making connections to the Telegram API endpoint.api.telegram.org.Settings > Devices or Settings > Active Sessions). Terminate any unrecognized sessions immediately. Enable a local passcode or password for the Telegram application itself to provide an additional layer of protection for the session data.Training users not to download or execute applications from untrusted sources is the first line of defense against this attack vector.
Use application control or allowlisting to prevent unknown executables from running on endpoints.
Mapped D3FEND Techniques:
Modern endpoint security solutions can detect and block the malware based on its behavior, such as accessing sensitive files or the microphone.
Mapped D3FEND Techniques:
Kaspersky reports that the campaign utilizing the 'Still Toolkit' began.
Kaspersky publishes its research on the Armored Likho 'Still Toolkit' campaign.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.