Critical

Armored Likho expands its cyber-espionage toolkit

Securelist
Actively Exploited

Overview

Kaspersky researchers have identified a new cyber-espionage campaign linked to the group Armored Likho. This campaign masquerades as a fundraising initiative and uses a newly developed tool called the Still Toolkit, which is specifically designed to steal data from Telegram and eavesdrop on users. The implications of this attack are significant, particularly for individuals and organizations that rely on Telegram for communication. Users should be cautious about unsolicited fundraising requests and consider enhancing their security measures to protect sensitive information. This incident illustrates the ongoing risks posed by sophisticated cyber-espionage tactics, which continue to evolve and target popular communication platforms.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Telegram
  • Action Required: Users should be cautious about unsolicited fundraising requests and consider enhancing their security measures.
  • Timeline: Newly disclosed

Original Article Summary

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Impact

Telegram

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should be cautious about unsolicited fundraising requests and consider enhancing their security measures.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Kaspersky.

Related Coverage

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

darkreading

Researchers have identified a group of hackers known as 'Jewelbug' who are operating a dual-purpose cyber operation. This group is engaging in both state-sponsored espionage and cryptocurrency theft, using a single web panel to manage their activities. The findings suggest that these attackers are not only targeting sensitive information on behalf of nation-states but are also financially motivated, seeking to steal funds from cryptocurrency exchanges and users. This dual approach raises concerns about the increasing overlap between state-sponsored hacking and financial crime, making it harder for organizations and individuals to protect themselves. The implications of this could be significant, as it blurs the lines between traditional cybersecurity threats and those driven by financial gain.

Aug 13, 2026

White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

SecurityWeek

The White House is taking action against foreign cybercrime gangs by mobilizing security firms to assist in operations aimed at tackling these threats. Companies that participate may be required to post a $1 million bond, which they would lose if they fail to meet certain operational standards. This move comes amid growing concerns about the impact of cybercrime on national security and the economy. By engaging private security firms, the government aims to bolster its capabilities in combating sophisticated cyber threats that often operate across borders. This initiative reflects a proactive approach to enhance cybersecurity measures and protect against increasingly organized and dangerous cybercriminal activities.

Aug 13, 2026

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

SecurityWeek

A serious vulnerability in VMware's vCenter software has been identified, tracked as CVE-2026-59310. This directory traversal flaw allows remote attackers to execute arbitrary code on affected systems, posing a significant risk to users. Organizations that rely on vCenter for managing virtualized environments should prioritize addressing this issue. The potential for exploitation means that attackers could gain control over systems, leading to data breaches or other malicious activities. It's crucial for companies to apply any available patches or updates to safeguard their infrastructure.

Aug 13, 2026

ICO Reprimands Criminal Records Office After 2023 Breach

Infosecurity Magazine

The Information Commissioner's Office (ICO) has reprimanded the Association of Chief Police Officers Criminal Records Office (ACRO) following a data breach that occurred in 2023. The breach was attributed to failures in patch management and security monitoring, which allowed unauthorized access to sensitive information. As a result, individuals whose criminal records were managed by ACRO may have had their personal data exposed. This incident raises concerns about the handling of sensitive information by governmental organizations and the potential risks to privacy and security for those affected. The ICO's action serves as a reminder that even agencies tasked with law enforcement must prioritize robust cybersecurity measures to protect citizen data.

Aug 13, 2026

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Help Net Security

Cisco has reported a high-severity vulnerability, designated as CVE-2026-20349, that attackers are using to cause temporary disruptions in the operation of Cisco firewalls. This flaw has been recognized by the Cybersecurity and Infrastructure Security Agency (CISA) and is included in their catalog of known exploited vulnerabilities. US civilian federal agencies are required to address this issue by August 14, 2026. While Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation in August, specific details regarding the attacks have not been disclosed. The urgency for remediation highlights the potential risks to organizations relying on Cisco’s firewall products.

Aug 13, 2026

Belgium's eID Authentication Opens Citizen Accounts to RCE

darkreading

Belgium's electronic ID system has suffered a significant breach due to serious vulnerabilities found in a crucial browser extension. This compromise means that unauthorized individuals could potentially access citizen accounts, revealing sensitive personal information. The issue raises concerns not just about Belgium's system but also highlights broader risks associated with browser extensions in general. As more services rely on digital identities, the security of these systems becomes increasingly important. Citizens using the eID system should be aware of the risks and consider additional security measures to protect their accounts.

Aug 13, 2026