Перейти к содержанию

Charity Becomes Bait for Cyber Espionage Attack on Russian Organizations

Kaspersky Lab experts in May 2026 identified a new cyber espionage campaign by the Armored Likho group. Russian organizations in the public sector, IT, and education were targeted. To infect victims, attackers use a fake application that mimics a service for sending aid through charitable foundations.

The program acts as a dropper: after launch, it prompts the user to log in, and then displays a catalog of goods for alleged humanitarian shipments. While the victim browses, the application secretly installs malicious components.

The new set of tools has been named Still Toolkit. One of its components, Still Sync, is designed to steal Telegram session data. With this, attackers can gain access to accounts, correspondence, and media files via the Telegram API.

The second module, Still Audio, allows for covert recording of conversations. It monitors the audio stream, recognizes speech, and transmits recordings to the attackers' server.

According to experts, the appearance of these components indicates the further development of Armored Likho's arsenal and the expansion of the group's data collection capabilities during targeted attacks.