~/f4n6 $ grep -r "Armored Likho expands its cyber-espionage toolkit" ./investigations/ --include="*.md"

Armored Likho expands its cyber-espionage toolkit

Jeff Davies 13 Aug 2026 8 min read

1. Executive summary

Kaspersky GReAT published details of a May 2026 cyber-espionage campaign by the actor "Armored Likho" (also referred to as "Eagle Werewolf") targeting individuals and organisations across multiple sectors in Russia, including the public sector, IT, and education. The campaign deploys a new Rust-based toolset called the "Still Toolkit," comprising two implants: Still Sync, which steals Telegram session data and autonomously exfiltrates chat histories and media via the Telegram API, and Still Audio, a covert audio surveillance implant that performs voice-activity detection and records conversations. Attribution to Armored Likho is unconfirmed — neither "Armored Likho" nor "Eagle Werewolf" has a MITRE ATT&CK profile in the verified reference data — and the assessment rests on code-level overlap with prior campaigns as documented in a single vendor report. EMEA financial services with operations, staff, or third parties in Russia should treat the Telegram session-theft and audio-surveillance capabilities as a direct risk to sensitive communications.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The campaign targets individuals and organisations in Russia via social engineering and bespoke malware; while a compromise would trigger general ICT incident management obligations, no fact in this item is distinctive enough to change what a client must do under a specific article listed in the regulatory reference.

3. Technical analysis & attack chain

Attribution caveat: "Armored Likho" and "Eagle Werewolf" have no MITRE ATT&CK profiles in the verified reference data; attribution is unconfirmed. The assessment rests on code-level overlap with prior campaigns (shared sysmarker hashing, shared Blowfish/ECB key, shared ICRYPTMP header format) documented in a single Kaspersky report. Single-sourced; verify before enforcement.

Attack chain (confirmed steps from source)

  1. Initial access — fake donation app. The attacker delivers a dropper application disguised as a Russian charitable donation service. The distribution method is unknown. The dropper is written in Rust on the Tauri framework and presents a graphical login form requiring a password (presumably attacker-supplied). Multiple samples were obtained, each posing as a different Russian foundation.
  2. Decoy activity. After the user enters a valid password, the app displays a clickable catalog of donatable items. Item and category data is fetched from orderapiserver[.]info via the public/categories and public/products HTTP endpoints, lending the app legitimacy.
  3. Payload deployment. While the user browses the catalog, the dropper decrypts and launches the payload in the background. The decryption and launch mechanism is unchanged from the group's February 2026 campaign.
  4. Still Sync — registration. Still Sync (Rust, async/Tokio, gRPC, FlatBuffers serialisation, HTTP or HTTPS per C2 URL) reads configuration from environment variables set by the attacker, including a C2 URL (https://tg4service[.]com:443), a tdata path, and a tdata password. It collects system information (username, computer name, OS version, etc.), concatenates it with colon separators, SHA-256 hashes the string, and stores the hash under the key sysmarker. It then POSTs the collected data and agent version to /still.rpc.Sync/RegisterMachine. The server returns a machine_id used for subsequent requests.
  5. Still Sync — settings retrieval. Sync sends a POST request with machine_id to /still.rpc.Sync/GetMachineSettings. The server returns settings including tdata path, tdata password, scan_portable flag, and fetch_telegram flag. No malicious actions occur until both registration and settings retrieval complete.
  6. Still Sync — Telegram session theft. Sync searches for the Telegram tdata folder across standard and (if scan_portable is set) nonstandard directories. It POSTs a list of tdata files to /still.rpc.Sync/CheckFiles; the server responds with instructions on which files to upload, avoiding re-receipt. If standard file access fails, Sync falls back to three SeBackupPrivilege-abuse mechanisms: CreateFileW with FILE_FLAG_BACKUP_SEMANTICS, and two additional methods (the source names the privilege and the first API call explicitly).
  7. Still Sync — Telegram data collection. If fetch_telegram is enabled, Sync launches a thread that authenticates to Telegram using the stolen tdata, then collects and exfiltrates account information including chat logs and media files via the Telegram API.
  8. Still Sync — persistence. If the --console argument is absent, Sync creates a Windows service named TReload to persist in the background.
  9. Still Sync — command-line arguments. --console (console mode), --version (print version and exit), --firefly (trace thread writing errors to a hidden file named bin in the executable's folder), --db (debug mode with detailed logging).
  10. Still Audio — deployment and initialisation. Still Audio (Rust) is saved to disk as IntAudio.exe. On launch it extracts and loads libmp3lame.dll (MP3 encoder) from inside the executable. If --console is absent, it creates a service named auxhost and runs in the background. It creates logfile.log for logging.
  11. Still Audio — C2 resolution. The C2 address is read from the STILL_AUDIO_SYNC_ADDR environment variable; if unset, it falls back to STILL_SYNC_ADDR (shared with Sync); if neither is set, it defaults to https://srwinservice[.]com. If the C2 is unreachable for three days, Still Audio uses a Dead Drop Resolver: it fetches hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json from a GitHub repository (a fork of a popular project). The C2 URL inside is Base64-encoded and encrypted with Blowfish in ECB mode using the key 5c8e153228edd3c6cbf75684 (lowercase string). This exact algorithm and key match older AquilaRAT samples.
  12. Still Audio — registration. Audio POSTs system information plus a list of available audio input devices to /still.rpc.Audio/RegisterAudioMachine. The server responds with settings including vad_threshold, max_silence_duration (default 320), and recording parameters.
  13. Still Audio — voice-activity detection and recording. Audio captures raw samples from the input device. It implements a custom RMS-based voice-activity detection algorithm (no third-party libraries). If RMS meets or exceeds vad_threshold, recording starts. A pre-buffer captures samples just before the recording moment. A sequence of max_silence_duration samples below the threshold ends the recording (approximately 7ms of silence at 44.1kHz). The implant does not hide microphone usage; it appears in Windows settings as "Intel Audio."
  14. Still Audio — exfiltration. Recordings are encoded with libmp3lame and POSTed to /tgfrg on the C2 server, with a Client-Id header containing the machine_id from registration.

Infrastructure: Eight domains across multiple hosting providers and ASNs, registered between December 2025 and May 2026. No direct domain/IP overlap with the February campaign, though structural similarities exist.

Kaspersky detection names: Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.

4. Mitigation & containment

P1 — within 24 hours

  • Block the eight C2 and support domains at DNS, web proxy, and firewall egress: orderapiserver[.]info, tg4service[.]com, srwinservice[.]com, screenserv[.]com, windowserv[.]net, managementapiservice[.]com, service8date[.]com, updateservs[.]com.
  • Block the associated IP addresses at the perimeter: 187.127.153[.]38, 159.198.37[.]74, 213.252.244[.]123, 23.26.237[.]250, 23.27.24[.]30, 188.212.124[.]178, 145.223.69[.]143, 145.223.68[.]66.
  • Block or monitor access to the Dead Drop Resolver URL: raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json. If broad blocking of raw.githubusercontent.com is not feasible, implement a proxy rule for this specific path.
  • Add the nine file hashes (MD5) to EDR blocklists and SIEM correlation rules — see §5 for values.

P2 — within 72 hours

  • Deploy EDR detection rules for the persistence mechanisms: creation of a Windows service named TReload or auxhost. See §6 for Sigma rules.
  • Hunt for IntAudio.exe on endpoints and review any process appearing as "Intel Audio" in Windows microphone-access logs.
  • Audit Telegram tdata folder access patterns. Monitor for processes other than the legitimate Telegram client reading %APPDATA%\Telegram Desktop\tdata or equivalent paths.
  • Review Windows Event Logs for SeBackupPrivilege abuse — specifically CreateFileW calls with FILE_FLAG_BACKUP_SEMANTICS targeting Telegram data directories.
  • Search endpoint file systems for a hidden file named bin in the same directory as unknown executables (Still Sync trace output).

P3 — within 7 days

  • Ensure Kaspersky endpoint products (where deployed) are current and the detection signatures Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic are active.
  • Brief staff in Russia or adjacent regions on the donation-app social engineering vector. Advise that any unsolicited application requesting a password to access a donation catalog is a confirmed attack pattern.
  • Review Telegram session activity for accounts associated with at-risk staff; terminate and re-key sessions where anomalous API access is observed.
  • Assess whether the GitHub repository mmarln/pi-mono or its forks have been accessed from corporate networks.

5. Indicators of compromise

Type Value Confidence Source
md5 C1D1EE16B92E6A138FFA048855F75D7D High Kaspersky GReAT
md5 17674B250D8B422A50A86C9FF207186D High Kaspersky GReAT
md5 62801F6223E860A7CCA271522E303B2D High Kaspersky GReAT
md5 68F0365D2FA8C828D012D8859E52A773 High Kaspersky GReAT
md5 4BD7C352AE277B0E38D07BEEDD4DD507 High Kaspersky GReAT
md5 D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD High Kaspersky GReAT
md5 2CA8ADBAB98EBE305EACF272CF48F5A0 High Kaspersky GReAT
md5 3AC41B097236A7723821848AE31EF141 High Kaspersky GReAT
md5 439255736797BC88BD19F282449E0436 High Kaspersky GReAT
domain orderapiserver[.]info High Kaspersky GReAT
domain tg4service[.]com High Kaspersky GReAT
domain srwinservice[.]com High Kaspersky GReAT
domain screenserv[.]com High Kaspersky GReAT
domain windowserv[.]net High Kaspersky GReAT
domain managementapiservice[.]com High Kaspersky GReAT
domain service8date[.]com High Kaspersky GReAT
domain updateservs[.]com High Kaspersky GReAT
ipv4 187.127.153[.]38 High Kaspersky GReAT
ipv4 159.198.37[.]74 High Kaspersky GReAT
ipv4 213.252.244[.]123 High Kaspersky GReAT
ipv4 23.26.237[.]250 High Kaspersky GReAT
ipv4 23.27.24[.]30 High Kaspersky GReAT
ipv4 188.212.124[.]178 High Kaspersky GReAT
ipv4 145.223.69[.]143 High Kaspersky GReAT
ipv4 145.223.68[.]66 High Kaspersky GReAT
url hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json High Kaspersky GReAT
filepath IntAudio.exe High Kaspersky GReAT
env_var STILL_SYNC_ADDR High Kaspersky GReAT
env_var STILL_AUDIO_SYNC_ADDR High Kaspersky GReAT
env_var STILL_SEND_PATH High Kaspersky GReAT
md5  C1D1EE16B92E6A138FFA048855F75D7D
md5  17674B250D8B422A50A86C9FF207186D
md5  62801F6223E860A7CCA271522E303B2D
md5  68F0365D2FA8C828D012D8859E52A773
md5  4BD7C352AE277B0E38D07BEEDD4DD507
md5  D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD
md5  2CA8ADBAB98EBE305EACF272CF48F5A0
md5  3AC41B097236A7723821848AE31EF141
md5  439255736797BC88BD19F282449E0436
domain  orderapiserver[.]info
domain  tg4service[.]com
domain  srwinservice[.]com
domain  screenserv[.]com
domain  windowserv[.]net
domain  managementapiservice[.]com
domain  service8date[.]com
domain  updateservs[.]com
ipv4  187.127.153[.]38
ipv4  159.198.37[.]74
ipv4  213.252.244[.]123
ipv4  23.26.237[.]250
ipv4  23.27.24[.]30
ipv4  188.212.124[.]178
ipv4  145.223.69[.]143
ipv4  145.223.68[.]66
url  hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json
filepath  IntAudio.exe
env_var  STILL_SYNC_ADDR
env_var  STILL_AUDIO_SYNC_ADDR
env_var  STILL_SEND_PATH

6. Detection

rule Still_Toolkit_Implants {
  meta:
    author = "Adverse Trace"
    date = "2026-08-13"
    reference = "https://securelist.com/armored-likho-still-toolkit/121033/"
    description = "Detects Still Sync and Still Audio Rust-based espionage implants by C2 endpoint paths, service names, and artefacts"

  strings:
    $rpc_sync_register = "/still.rpc.Sync/RegisterMachine" ascii
    $rpc_sync_settings = "/still.rpc.Sync/GetMachineSettings" ascii
    $rpc_sync_checkfiles = "/still.rpc.Sync/CheckFiles" ascii
    $rpc_audio_register = "/still.rpc.Audio/RegisterAudioMachine" ascii
    $audio_exfil = "/tgfrg" ascii
    $service_treload = "TReload" ascii
    $service_auxhost = "auxhost" ascii
    $env_still_sync = "STILL_SYNC_ADDR" ascii
    $env_still_audio_sync = "STILL_AUDIO_SYNC_ADDR" ascii
    $env_still_send = "STILL_SEND_PATH" ascii
    $sysmarker = "sysmarker" ascii
    $libmp3lame = "libmp3lame.dll" ascii
    $blowfish_key = "5c8e153228edd3c6cbf75684" ascii
    $dead_drop_path = "mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json" ascii
    $client_id_header = "Client-Id" ascii
    $firefly = "--firefly" ascii
    $trace_file = "logfile.log" ascii

  condition:
    4 of them
}
title: Armored Likho Still Toolkit Service Creation
id: 7a3c1f2e-8b4d-4e6a-9c5f-1d2e3f4a5b6c
status: experimental
description: Detects creation of Windows services used by Still Sync (TReload) and Still Audio (auxhost) for persistence
author: Adverse Trace
date: 2026/08/13
references:

  - https://securelist.com/armored-likho-still-toolkit/121033/
logsource:
  product: windows
  service: system
detection:
  selection_service_create:
    EventID: 7045
    ServiceName:

      - "TReload"
      - "auxhost"
  condition: selection_service_create
falsepositives:

  - Unknown — service names are generic enough to warrant correlation with process creation events
level: high
title: Armored Likho Still Audio Microphone Access by IntAudio.exe
id: 8b4d2f3e-9c5e-4f7b-ad6c-2e3f4a5b6c7d
status: experimental
description: Detects IntAudio.exe (Still Audio implant) accessing microphone, appearing as "Intel Audio" in Windows settings
author: Adverse Trace
date: 2026/08/13
references:

  - https://securelist.com/armored-likho-still-toolkit/121033/
logsource:
  product: windows
  service: security
detection:
  selection_process:
    EventID: 4663
    ProcessName|endswith: "IntAudio.exe"
    ObjectType: "File"
    ObjectName|contains: "microphone"
  condition: selection_process
falsepositives:

  - Legitimate Intel audio drivers do not use this executable name
level: high

7. Sources

  • Kaspersky GReAT (Securelist) — "Armored Likho expands its cyber-espionage toolkit" — https://securelist.com/armored-likho-still-toolkit/121033/ — 2026-08-13
  • Kaspersky GReAT (Securelist) — "Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign" — https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/ — (prior campaign context, February 2026)

8. Adverse Trace position

This is a targeted cyber-espionage campaign with a focused geographic scope (Russia) but capabilities that are directly relevant to EMEA financial services with Russian operations, staff, or third-party relationships. The Still Toolkit represents a meaningful capability expansion: Telegram session theft with autonomous API-based data collection and covert audio surveillance together cover two high-value communication channels. The Rust/Tauri dropper and gRPC/FlatBuffers C2 architecture indicate a maturing development effort designed for long-term use. Attribution to Armored Likho/Eagle Werewolf is unconfirmed (no MITRE ATT&CK profiles in verified reference data) and rests on a single vendor's code-overlap analysis — we assess the technical detail as high-confidence but the attribution as moderate-confidence. We will continue monitoring for infrastructure rotation, new Still Toolkit modules, and any expansion of targeting beyond Russia. Clients with exposure to the region should prioritise the P1 domain/IP blocks and the §6 detection rules immediately.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies