Armored Likho expands its cyber-espionage toolkit
The campaign uses fundraising and Starlink lures as bait and delivers a new toolkit generation that steals Telegram data and eavesdrops on victims.
CTI status
As of:
Last pipeline run:
Source reliability
Information credibility
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
The campaign uses fundraising and Starlink lures as bait and delivers a new toolkit generation that steals Telegram data and eavesdrops on victims.
The flaw allows local attackers to escalate privileges in the Linux kernel and affects unpatched Ubuntu systems.
Bundling several already-patched zero-days into a circulating exploit kit lets even less skilled espionage-motivated actors exploit them, making the window between patch availability and patch deployment the decisive risk factor.
The report provides a quarterly overview of the threat landscape for industrial automation systems and documents new APT malware attributed to Mirage Kitten, which is strategically relevant for production environments.
The report summarizes multiple vulnerabilities in Google Chrome without specific CVEs or exploit details; timely patch management remains necessary.
The vulnerability requires user interaction and affects widely used compression software installed in many corporate environments; a CVE ID is not yet available.
This BSI advisory lists multiple Edge vulnerabilities without CVE references and without indication of active exploitation.
The report describes a novel attack technique (Benchmaxxing) that goes beyond pure patch information and provides new TTPs for defense.
The advisory summarises multiple Linux kernel vulnerabilities without providing specific CVEs or evidence of active exploitation.