Skip to content
Auto-CTI
Back to today
NEW Armored Likho CRITICAL B3

Armored Likho expands its cyber-espionage toolkit

B Securelist ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The campaign uses fundraising and Starlink lures as bait and delivers a new toolkit generation that steals Telegram data and eavesdrops on victims.

Description

The report describes a new campaign by the group tracked as Armored Likho, also known as Mirage Kitten, UNC1549, Smoke Sandstorm and Nimbus Manticore. Malicious droppers disguised as documents or applications related to Starlink activation or fundraising efforts serve as the initial infection vector. The campaign delivers a new toolkit generation, including the Tokio-based Sync application as well as the previously undocumented NightLedger, ArcBridge and BridgeHead malware. The activity overlaps significantly with earlier campaigns from November 2024 and February 2026 and aims at stealing Telegram data and eavesdropping on victims. The malware is attributed to a state-sponsored actor with a cyber-espionage focus.

Risk score

85
strategic relevance
0.85

Path: strategic

ESC