Armored Likho — APT Profile
Kaspersky publicly named Armored Likho in July 2026 as a previously undocumented APT hitting government agencies and electric power operators in Russia, Brazil and Kazakhstan, alongside broader campaigns against Russian corporations, IT firms, educational institutions and private individuals. BI.ZONE tracks overlapping activity as Eagle Werewolf, which it says has been active since at least May 2023 against Russian state bodies, industrial companies and people involved in drone manufacturing and engineering, and which compromised a drone-focused Telegram channel in February 2026 to spread malware. The group favours droppers written in Rust on the Tauri framework and disguised as legitimate desktop applications, with lures themed around Starlink activation and charitable fundraising, and it has also used spear-phishing archives whose LNK shortcuts abuse ZDI-CAN-25373 to hide their command lines. Its toolset includes the Rust backdoor AquilaRAT, which persists as a bogus MicrosoftOfficeUpdate service, the Python-based BusySnake Stealer, the Go2Tunnel reverse SSH tunneller, abuse of RustDesk, and the Rust-based Still Toolkit that Kaspersky found in May 2026: Still Sync steals Telegram Desktop session data and then uses the Telegram API to pull chats, member lists and media, while Still Audio detects speech on the microphone and uploads recorded conversations. Kaspersky notes that some of the group's loaders carry verbose comments and emoji bullet points suggesting they were generated with a large language model. No vendor has publicly attributed the group to a nation state.Also tracked as
Eagle Werewolf
IntelFusions coverage (2)
- Spyware steals Telegram chats and secretly records audio 2026-08-13 · Nation-State
- New APT Armored Likho hits governments with AI-built malware loaders 2026-07-03 · Nation-State
Tools & malware
- AquilaRAT RAT
- BusySnake Stealer Stealer
- Go2Tunnel Tunneling tool
- RustDesk Remote access tool
- Still Audio Spyware
- Still Sync Stealer