HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Armored Likho Deploys Rust‑Based ‘Still Toolkit’ to Steal Telegram Sessions and Conduct Covert Audio Surveillance

Kaspersky reports that the Armored Likho group is using a Rust‑written ‘Still Toolkit’ to steal Telegram session data and capture covert audio. The campaign targets individuals and organizations in Russia, highlighting the need for robust SOC 2 access‑control monitoring and security‑awareness controls.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 securelist.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
securelist.com

Armored Likho Deploys Rust‑Based ‘Still Toolkit’ to Steal Telegram Sessions and Conduct Covert Audio Surveillance

What Happened — In May 2026 Kaspersky uncovered a new cyber‑espionage campaign by the Armored Likho (aka Eagle Werewolf) group. The attackers distribute a fake donation‑app dropper that installs the Rust‑written Still Toolkit. Its components, Still Sync and Still Audio, harvest Telegram session data for persistent account access and record ambient audio for covert surveillance, respectively.

Why It Matters for Compliance & Audit Readiness

  • The campaign illustrates how stolen authentication tokens bypass traditional password controls, a scenario SOC 2 access‑control policies are designed to detect and mitigate.
  • Continuous monitoring of privileged‑access usage and evidence of robust security‑awareness training become critical audit artifacts when credential‑theft vectors are in play.

Who Is Affected — Private individuals and organizations across Russia, notably large corporations, public‑sector bodies, IT firms, and educational institutions.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (Logical Access Controls) and CC6.2 (User Access Provisioning) and ensure evidence of periodic access‑review logs.
  • Deploy endpoint detection that flags unauthorized Telegram API calls and enforce MFA for all messaging platforms.
  • Reinforce security‑awareness programs with phishing‑simulation exercises that include fake‑app lures.

Technical Notes

  • Initial infection vector: malicious Rust/Tauri‑based donation app dropper.
  • Still Sync extracts Telegram session tokens from local storage, enabling API‑driven data exfiltration.
  • Still Audio captures live microphone streams, performs speech detection, and uploads recordings to a C2 server.
  • Detected by Kaspersky as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.

Source: SecureList – Armored Likho expands its cyber‑espionage toolkit

📰 Original Source
https://securelist.com/armored-likho-still-toolkit/121033/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →