Skip to main content
LiMP VPN
All news

Armored Likho: Telegram Spy Suite and Covert Microphone Recording

Armored Likho: Telegram Spy Suite and Covert Microphone Recording

In short: Kaspersky GReAT has exposed a new cyber-espionage campaign called Armored Likho targeting Russian organizations in the government, IT, and education sectors. Attackers deploy the Still Toolkit — a two-module suite where Still Sync steals Telegram session data and Still Audio covertly records conversations through the device microphone. The infection vector is a trojanized fake charitable donation application.

What Researchers Discovered

In August 2026, Kaspersky's Global Research and Analysis Team (GReAT) published findings from an ongoing investigation into a new espionage campaign named Armored Likho. First detected in May 2026, the campaign had already targeted multiple Russian organizations across the government sector, IT industry, and educational institutions by the time of publication.

The centerpiece of the discovery is the Still Toolkit — two independent but complementary espionage modules. Their combination is what makes Armored Likho particularly dangerous: operators gain simultaneous access to the victim's digital communications and real-world physical environment. For background on how attackers monetize stolen account data, see our overview of how infostealers steal passwords and cookies.

Still Sync: How Telegram Accounts Are Hijacked

The first module — Still Sync — targets Telegram. The stealer extracts Telegram session files from the infected device and transmits them to attacker-controlled servers. With an active session file, the operator can log into the victim's account via the Telegram API and access private and group conversations, media files, documents, and the full contact list.

Critically, no password or SMS code is required to hijack the account. Telegram stores session files locally on the device, and possessing that file is equivalent to being the authenticated user. This means two-step verification does not protect against session theft after device compromise — the attacker logs in as an already-authorized session, bypassing the authentication challenge entirely.

Still Audio: Covert Microphone Surveillance

The second module — Still Audio — transforms the infected Windows machine into a covert listening device. The implant silently activates the microphone in the background, analyzes incoming audio, recognizes speech, records conversations, and automatically transmits audio files to the attackers' command-and-control infrastructure.

The surveillance is invisible to the user: no system warnings appear, no microphone indicator activates in the system tray, and no permission dialogs pop up. From the employee's perspective, it is a normal working day — while every conversation near the infected machine is being streamed to the campaign operators.

According to Kaspersky GReAT's analysis, both modules share a common architecture and command-and-control mechanisms, indicating they were designed as a single expandable ecosystem with planned capability growth in future versions.

How Infection Happens

The attack relies on social engineering under the cover of charitable giving. Targets receive a fake application that mimics a charitable aid foundation platform. On launch, the dropper presents an authentication form requiring a pre-shared password — this creates an illusion of legitimacy and lowers the victim's guard.

Once "authenticated," the user sees a functional product catalog with working links, raising no suspicion. Meanwhile, the dropper silently decrypts and launches the malicious payload in the background — Still Toolkit components establish persistence and begin operating. The charitable disguise is likely deliberate: organizations receiving aid tend to apply less scrutiny to software from "benefactors" than to external installers. For context on social engineering methods, see our guide on remote access scams.

Who Is at Risk and How to Protect Yourself

Kaspersky GReAT identified the current targets as Russian government agencies, IT companies, and educational institutions. However, the methodology applies to any organization whose employees use Telegram as a work messenger.

Practical protective measures:

  • Only install software from verified sources. Third-party applications — even those arriving through colleagues or "official" partners — should be reviewed by IT security before installation.
  • Never enter credentials into unfamiliar applications. An authentication form in unverified software is a classic social engineering trap designed to bypass user vigilance.
  • Regularly terminate Telegram sessions on unused devices. In Telegram settings: Devices → Terminate all other sessions. Regular rotation limits the window during which stolen session files can be exploited.
  • Enable Telegram login notifications. Even if a session was stolen, an immediate alert about a new login from an unknown device allows you to revoke unauthorized access before significant damage occurs.
  • Use network-level encryption. LiMP VPN encrypts all device traffic, making data interception in transit significantly harder and complicating exfiltration from spyware modules to C2 servers on monitored network segments.
  • Monitor outbound network activity. Unusual outbound traffic at odd hours is a potential indicator of a running spyware implant. Corporate DLP and SIEM solutions can surface these anomalies in time.

Learn more about protecting your device and data on the LiMP VPN pricing page.

Sources

Armored Likho: Telegram Spy Suite and Covert Microphone Recording