Armored Likho Steals Telegram Sessions for Espionage
Kaspersky said Armored Likho, also known as Eagle Werewolf, ran a new espionage campaign in May 2026 that used a fake donation app to deliver a Rust-based Still Toolkit. The toolkit includes Still Sync, which steals Telegram session data, and Still Audio, which supports covert audio surveillance.
The session data matters because it is a standing login, not just a password. Once the attacker has it, Telegram’s own API can be used to pull chats, media, and other account data even after the original device is cleaned; the audio implant can also detect speech, record conversations, and send them out.
That makes the compromise account-level and persistent for anyone whose Telegram session is taken, including organizations where messaging is part of daily work. The campaign was reported against targets in Russia across government, IT, education, and private industry, so the lasting exposure sits with the account and its history, not only the infected host.