Armored Likho — APT Profile

Kaspersky publicly named Armored Likho in July 2026 as a previously undocumented APT hitting government agencies and electric power operators in Russia, Brazil and Kazakhstan, alongside broader campaigns against Russian corporations, IT firms, educational institutions and private individuals. BI.ZONE tracks overlapping activity as Eagle Werewolf, which it says has been active since at least May 2023 against Russian state bodies, industrial companies and people involved in drone manufacturing and engineering, and which compromised a drone-focused Telegram channel in February 2026 to spread malware. The group favours droppers written in Rust on the Tauri framework and disguised as legitimate desktop applications, with lures themed around Starlink activation and charitable fundraising, and it has also used spear-phishing archives whose LNK shortcuts abuse ZDI-CAN-25373 to hide their command lines. Its toolset includes the Rust backdoor AquilaRAT, which persists as a bogus MicrosoftOfficeUpdate service, the Python-based BusySnake Stealer, the Go2Tunnel reverse SSH tunneller, abuse of RustDesk, and the Rust-based Still Toolkit that Kaspersky found in May 2026: Still Sync steals Telegram Desktop session data and then uses the Telegram API to pull chats, member lists and media, while Still Audio detects speech on the microphone and uploads recorded conversations. Kaspersky notes that some of the group's loaders carry verbose comments and emoji bullet points suggesting they were generated with a large language model. No vendor has publicly attributed the group to a nation state.

Also tracked as

Eagle Werewolf

IntelFusions coverage (2)

Tools & malware

Vendor research

Read the full analysis on IntelFusions