A recent cyber-espionage campaign attributed to the group known as Armored Likho has been identified targeting individuals and organizations in Russia. The operation employs a deceptive donation application to infiltrate systems, subsequently deploying the Still Toolkit—a sophisticated suite designed to hijack Telegram accounts and clandestinely record conversations.
The significance of this campaign lies in its dual approach: compromising Telegram sessions to access private communications and activating microphone surveillance to capture live conversations. This method allows attackers to gather extensive personal and organizational information, posing substantial privacy and security threats.
Upon execution, the counterfeit donation app presents a login interface and a catalog of items, creating an illusion of legitimacy. Meanwhile, in the background, it installs malicious components without the user’s knowledge.
Still Sync: Exploiting Telegram Sessions
The first component, Still Sync, targets session data from Telegram Desktop. By accessing this data, attackers can assume control of authenticated accounts without requiring login credentials. This enables them to collect a wide array of information, including account details, private chats, group memberships, channels, and media files up to 250MB in size. Additionally, Still Sync can extract contact lists, phone numbers, documents, stickers, photos, and other sensitive data, significantly amplifying the potential impact of a single device compromise.
Still Sync registers the infected device with a command server and awaits instructions to activate its data collection features. It searches both standard and portable Telegram installations and can employ backup methods if direct file access is obstructed. This approach underscores the importance of securing local Telegram data, as session hijacking can occur even with two-step verification enabled.
Still Audio: Covert Conversation Recording
The second component, Still Audio, enhances surveillance capabilities by monitoring the device’s microphone. It activates recording when ambient sound surpasses a predefined threshold, captures audio, converts it to MP3 format, and transmits it to the attacker’s infrastructure. Operating as a Windows service, Still Audio attempts to conceal its presence; however, it may appear in the list of applications using the microphone under a name resembling legitimate audio components, providing a potential indicator for detection.
Notably, Still Audio includes a fallback mechanism that allows it to connect to alternative servers if the primary connection fails for three days, demonstrating the attackers’ commitment to maintaining persistent access.
Analysis of the campaign reveals code and infrastructure similarities with previous operations attributed to Armored Likho, also known as Eagle Werewolf. The integration of the Still Toolkit into their arsenal indicates a strategic evolution towards more comprehensive and persistent surveillance methods.
This development highlights the escalating sophistication of cyber-espionage tactics. Users are advised to exercise caution when downloading applications, especially those requesting sensitive permissions. Implementing robust security measures, such as enabling two-factor authentication, regularly updating software, and monitoring device activity, is crucial in mitigating the risks associated with such advanced threats.