Fake Fundraising App Used to Steal Telegram Sessions and Conduct Audio Surveillance
The Armored Likho group exploited users' trust by disguising malware as a legitimate fundraising application, a classic social engineering technique that bypasses technical defenses by targeting human behavior. Once installed, the 'Still Toolkit' harvested Telegram session data, effectively hijacking authenticated accounts without needing credentials — a serious access control failure rooted in unprotected session token storage. Covert audio surveillance further demonstrates how a single deceptive download can escalate into a full-scale espionage operation. This campaign underscores that end users remain the most exploitable attack surface when they lack awareness about verifying app authenticity and understanding the risks of third-party software.
Tactical Insight
Immediate actions
- Audit and remove any unauthorized or unverified applications from organizational and personal devices.
- Enable Telegram's active sessions monitoring and terminate any unrecognized sessions immediately.
- Report suspicious fundraising apps or links to your security team before downloading or sharing them.
Long-term improvements
- Enforce a Mobile Device Management (MDM) policy that restricts installation of apps from unverified or unofficial sources.
- Implement application allowlisting on endpoints to prevent unauthorized software from executing.
- Conduct regular security awareness training focused on social engineering, fake app campaigns, and phishing lures.
Detection measures
- Deploy endpoint detection and response (EDR) tools capable of identifying unauthorized audio recording or session token access activity.
- Monitor for anomalous Telegram login events, particularly those originating from unfamiliar IP addresses or geographies.
- Establish behavioral baselines on endpoints to flag unusual data exfiltration patterns associated with espionage toolkits.