Back to all lessons
Awareness Lessons
2 months ago

Fake Fundraising App Used to Steal Telegram Sessions and Conduct Audio Surveillance

The Armored Likho group exploited users' trust by disguising malware as a legitimate fundraising application, a classic social engineering technique that bypasses technical defenses by targeting human behavior. Once installed, the 'Still Toolkit' harvested Telegram session data, effectively hijacking authenticated accounts without needing credentials — a serious access control failure rooted in unprotected session token storage. Covert audio surveillance further demonstrates how a single deceptive download can escalate into a full-scale espionage operation. This campaign underscores that end users remain the most exploitable attack surface when they lack awareness about verifying app authenticity and understanding the risks of third-party software.

Tactical Insight

Immediate actions

  • Audit and remove any unauthorized or unverified applications from organizational and personal devices.
  • Enable Telegram's active sessions monitoring and terminate any unrecognized sessions immediately.
  • Report suspicious fundraising apps or links to your security team before downloading or sharing them.

Long-term improvements

  • Enforce a Mobile Device Management (MDM) policy that restricts installation of apps from unverified or unofficial sources.
  • Implement application allowlisting on endpoints to prevent unauthorized software from executing.
  • Conduct regular security awareness training focused on social engineering, fake app campaigns, and phishing lures.

Detection measures

  • Deploy endpoint detection and response (EDR) tools capable of identifying unauthorized audio recording or session token access activity.
  • Monitor for anomalous Telegram login events, particularly those originating from unfamiliar IP addresses or geographies.
  • Establish behavioral baselines on endpoints to flag unusual data exfiltration patterns associated with espionage toolkits.