Armored Likho Abuses GitHub as Backup C2 Channel for Audio Surveillance Malware
Brief
Armored Likho, also known as Eagle Werewolf, has launched a new cyber-espionage campaign targeting individuals and organizations in Russia.
The group used fake donation applications as bait, but its latest malware toolkit is the bigger concern. The attackers can steal Telegram session data, collect messages and media, and secretly record audio from infected Windows systems.
The campaign, observed in May 2026, affected private users as well as organizations in the public sector, IT, education, and large businesses.
Researchers linked the activity to earlier Armored Likho operations through shared code, encryption methods, infrastructure patterns, and device-identification logic.
The initial infection begins with a malicious Rust-based application built with the Tauri framework. It pretends to be a donation service connected to Russian foundations.
