[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxZsKaGN8PKNR2D-VYtrOCBkUXMIYvbWKE1y2B1EQxe8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"12d29589-5d20-449d-9903-76d381bc6601","fake-fundraising-app-used-to-steal-telegram-sessions-and-conduct-audio-surveillance","28aac862-4a16-4179-a9cc-589049808679","Fake Fundraising App Used to Steal Telegram Sessions and Conduct Audio Surveillance","The Armored Likho group exploited users' trust by disguising malware as a legitimate fundraising application, a classic social engineering technique that bypasses technical defenses by targeting human behavior. Once installed, the 'Still Toolkit' harvested Telegram session data, effectively hijacking authenticated accounts without needing credentials — a serious access control failure rooted in unprotected session token storage. Covert audio surveillance further demonstrates how a single deceptive download can escalate into a full-scale espionage operation. This campaign underscores that end users remain the most exploitable attack surface when they lack awareness about verifying app authenticity and understanding the risks of third-party software.","**Immediate actions:**\n- Audit and remove any unauthorized or unverified applications from organizational and personal devices.\n- Enable Telegram's active sessions monitoring and terminate any unrecognized sessions immediately.\n- Report suspicious fundraising apps or links to your security team before downloading or sharing them.\n\n**Long-term improvements:**\n- Enforce a Mobile Device Management (MDM) policy that restricts installation of apps from unverified or unofficial sources.\n- Implement application allowlisting on endpoints to prevent unauthorized software from executing.\n- Conduct regular security awareness training focused on social engineering, fake app campaigns, and phishing lures.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools capable of identifying unauthorized audio recording or session token access activity.\n- Monitor for anomalous Telegram login events, particularly those originating from unfamiliar IP addresses or geographies.\n- Establish behavioral baselines on endpoints to flag unusual data exfiltration patterns associated with espionage toolkits.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 14 – Security Awareness and Skills Training","CIS Control 10 – Malware Defenses","NIST SP 800-53 AC-17 – Remote Access","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 AT-2 – Literacy Training and Awareness","NIST SP 800-53 AU-6 – Audit Record Review, Analysis, and Reporting","MITRE ATT&CK T1539 – Steal Web Session Cookie","MITRE ATT&CK T1418 – Software Discovery (Mobile)","GDPR Article 32 – Security of Processing","published","2026-08-13T10:21:47.995902+00:00","2026-08-13T10:21:47.668+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsecurelist.com\u002Farmored-likho-still-toolkit\u002F121033\u002F","armored-likho-expands-its-cyber-espionage-toolkit-42d8bf","Armored Likho expands its cyber-espionage toolkit",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]