Armored Likho Deploys Rust‑Based ‘Still Toolkit’ to Steal Telegram Sessions and Conduct Covert Audio Surveillance
What Happened — In May 2026 Kaspersky uncovered a new cyber‑espionage campaign by the Armored Likho (aka Eagle Werewolf) group. The attackers distribute a fake donation‑app dropper that installs the Rust‑written Still Toolkit. Its components, Still Sync and Still Audio, harvest Telegram session data for persistent account access and record ambient audio for covert surveillance, respectively.
Why It Matters for Compliance & Audit Readiness
- The campaign illustrates how stolen authentication tokens bypass traditional password controls, a scenario SOC 2 access‑control policies are designed to detect and mitigate.
- Continuous monitoring of privileged‑access usage and evidence of robust security‑awareness training become critical audit artifacts when credential‑theft vectors are in play.
Who Is Affected — Private individuals and organizations across Russia, notably large corporations, public‑sector bodies, IT firms, and educational institutions.
Recommended Actions
- Map the incident to SOC 2 CC6.1 (Logical Access Controls) and CC6.2 (User Access Provisioning) and ensure evidence of periodic access‑review logs.
- Deploy endpoint detection that flags unauthorized Telegram API calls and enforce MFA for all messaging platforms.
- Reinforce security‑awareness programs with phishing‑simulation exercises that include fake‑app lures.
Technical Notes
- Initial infection vector: malicious Rust/Tauri‑based donation app dropper.
- Still Sync extracts Telegram session tokens from local storage, enabling API‑driven data exfiltration.
- Still Audio captures live microphone streams, performs speech detection, and uploads recordings to a C2 server.
- Detected by Kaspersky as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.
Source: SecureList – Armored Likho expands its cyber‑espionage toolkit