TON Foundation says Telegram Web3 mini-apps have passed 100 million monthly active users, marking another major distribution milestone for one of crypto’s most consumer-facing ecosystems.
That number is big enough to grab attention, but it needs a careful read.
Monthly active users in Telegram mini-apps can include off-chain bot interactions, app sessions, and wallet-adjacent activity. It should not be treated as the same thing as 100 million on-chain TON wallets all making direct transactions.
Still, even with that caveat, the scale is impressive.
TON has something most crypto networks badly want: access to a massive messaging platform where users already spend time.
For more details, visit the official Ton platform.
TL;DR
TON-linked Telegram mini-apps have passed 100 million monthly active users.
The figure includes Telegram mini-app activity, not only on-chain wallet transactions.
TON Space and Telegram-based onboarding remain central to the ecosystem’s growth story.
Why Telegram Distribution Matters
Crypto adoption usually struggles with distribution.
Projects build wallets, exchanges, apps, games, and payment systems, then spend huge amounts trying to attract users. TON starts from a different place because it is closely tied to the Telegram environment.
That does not guarantee adoption.
But it gives TON a user funnel most chains do not have. If people can discover mini-apps inside a messaging app they already use, onboarding feels less alien than downloading a new wallet and learning a new ecosystem from scratch.
That is a real advantage.
Mini-Apps Are Not Just Wallets
The mini-app category is broad.
Some apps may involve games, rewards, bots, payments, trading, social features, or wallet interactions. That means the 100 million MAU number is not a pure measure of on-chain financial activity.
And that is fine, as long as it is explained clearly.
The point is that Telegram-based Web3 apps are reaching a large user base. The next question is how much of that activity converts into durable wallet usage, transactions, payments, and application revenue.
TON Space Helps The Wallet Story
TON Space gives the ecosystem a self-custody wallet route inside Telegram.
That matters because mini-app engagement becomes much more powerful if users can move from playing, earning, or interacting into actual wallet activity without leaving the environment. The smoother that step is, the stronger TON’s consumer crypto case becomes.
Most chains have to build consumer distribution from scratch.
TON can build inside a platform where communication and app discovery already happen.
Bot Activity Needs A Caveat
The source materials note that MAU counts include off-chain Telegram bot interactions alongside direct on-chain wallet transfers.
That caveat should not be buried.
Bot-driven ecosystems can produce huge engagement numbers, but not every interaction has the same economic value. A user clicking inside a mini-app is different from a user holding assets, making payments, or interacting with DeFi.
The quality of activity matters.
Still, engagement is the first step. Without users, none of the deeper metrics can follow.
The TON Market View
TON’s 100 million MAU milestone shows why the network remains one of the most interesting consumer crypto plays.
The number is not a clean on-chain wallet count, and it should not be treated like one. But it does show that Telegram mini-apps are operating at a scale most crypto products never reach.
Now the real test begins.
Can TON convert attention into lasting wallet adoption, useful payments, real transaction volume, and sustainable apps?
That is the question. But reaching 100 million monthly active mini-app users gives the ecosystem a serious platform to work from.
This article draws on TON Foundation materials and Tonstat ecosystem data.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by Ton. at Ton
Telegram crypto trading bots bring automated trading directly into the messaging app, allowing users to execute trades, monitor markets, and manage strategies through chat. For businesses, they offer opportunities to deliver convenient trading tools while creating new revenue streams.
Why Are Indian Crypto Traders Turning to Telegram?
Telegram has become an increasingly popular communication and trading environment for Indian crypto users. Its large crypto-focused communities, real-time communication, automated trading tools, P2P discussions, and access to Web3 services make it attractive to traders looking for faster ways to discover market opportunities. However, Telegram-based crypto activity also carries significant risks, including scams, fraudulent signals, wallet-security threats, and unverified trading services.
Key Reasons for Telegram’s Popularity
P2P Trading Communities: Telegram groups allow traders to connect with P2P participants, discuss payment methods, share market information, and explore trading opportunities outside traditional exchange interfaces.
Speed and Trading Bots: Automated Telegram trading bots can monitor markets, interact with decentralized exchanges (DEXs), and execute predefined actions rapidly. Bots are particularly popular among traders following newly launched tokens and highly volatile assets.
Trading Signals and Communities: Crypto-focused channels and groups provide market commentary, technical analysis, trading signals, token updates, and discussions that help users stay informed about fast-moving markets.
Web3 Accessibility: Telegram’s growing integration with blockchain and Web3 ecosystems has made it easier for users to discover wallets, decentralized applications, token communities, and blockchain-based services from a familiar messaging environment
Direct Communication: Traders can communicate directly with project teams, signal providers, bot operators, and other market participants, creating an active environment for sharing information and opportunities.
Major Risks to Keep in Mind
Scams and Fake Signals: Fraudulent Telegram channels may promote unrealistic returns, fake trading results, manipulated screenshots, impersonation schemes, or misleading investment opportunities.
Wallet Security Risks: Some trading bots or third-party services may request sensitive wallet permissions or private-key access. Giving a malicious service excessive permissions can potentially result in significant asset losses.
Unverified Projects: Token promotions and trading recommendations shared through Telegram may not always come from verified or trustworthy sources. Traders should independently research projects before committing funds.
Regulatory Considerations: Indian users should also consider applicable tax, financial, and regulatory requirements when participating in crypto-related activities.
What Is a Telegram Crypto Trading Bot?
A Telegram crypto trading bot is an automated software program that operates through Telegram, allowing users to interact with trading tools through chat commands, menus, or buttons. Depending on its architecture, the bot can connect to a user’s crypto wallet, interact with decentralized exchanges (DEXs), or connect to a centralized exchange (CEX) through API credentials.
Unlike conventional exchange interfaces, Telegram trading bots bring trading functions directly into a messaging environment, making it possible to monitor markets, configure trades, and execute transactions without constantly switching between different applications.
How Telegram Trading Bots Work
Telegram trading bots combine automated trading functionality with a chat-based interface.
1. Wallet or Exchange Connection
The first step is connecting the bot to a trading environment. A DEX-focused bot may create or connect to a dedicated wallet, while a CEX-focused bot can use API credentials to communicate with an exchange account.
2. Funding
For wallet-based trading, users transfer cryptocurrency to the wallet associated with the bot. The available balance can then be used for eligible transactions. Users should carefully review the custody and withdrawal mechanisms before depositing funds.
3. Trading Commands
Users can interact with the bot through commands or interactive buttons. Depending on the platform, they may configure parameters such as the trading pair, transaction amount, slippage tolerance, gas settings, stop-loss levels, or other strategy conditions.
4. Trade Execution
Once the required conditions are met, the bot processes the trade. For DEX transactions, it can interact with blockchain smart contracts, while CEX bots typically communicate with exchange APIs. Automation can reduce the time required to identify and respond to market movements.
Key Features and Use Cases
Token Sniping
Token-sniping functionality monitors newly launched tokens and liquidity events, allowing automated systems to attempt transactions as soon as predefined conditions are satisfied. Execution speed does not guarantee a successful or profitable trade, particularly during periods of extreme volatility.
Copy Trading
Copy-trading functionality allows users to follow selected wallets or trading strategies and automatically replicate eligible transactions according to predefined settings.
Automated Trading Strategies
Bots can support strategies such as grid trading, dollar-cost averaging (DCA), scheduled buying, take-profit orders, and stop-loss mechanisms. Automation allows predefined rules to operate without requiring the user to manually place every transaction.
Token and Contract Analysis
Some Telegram trading bots incorporate security-analysis tools that examine token contracts, liquidity conditions, ownership structures, or other risk indicators before a trade is submitted. These checks can help identify potential warning signs, but they cannot guarantee that a token or smart contract is safe.
Risks to Keep in Mind
Custody and Private-Key Risks
Some Telegram trading bots operate with dedicated wallets or require access to wallet credentials. If private keys or signing authority are compromised, users could lose control of their assets. A dedicated trading wallet with limited funds can reduce potential exposure.
Phishing and Impersonation
Telegram is also used by scammers to create fake bots, impersonate legitimate projects, and distribute malicious links. Users should verify bot identities through official project channels and avoid entering sensitive credentials into unknown interfaces.
Smart Contract and Software Risks
Trading bots depend on software, APIs, smart contracts, and blockchain infrastructure. Bugs, vulnerabilities, failed transactions, network congestion, or incorrect configurations can result in financial losses.
Market Volatility
Automation can execute trades quickly, but speed does not eliminate market risk. Low liquidity, price slippage, MEV activity, sudden price movements, and failed transactions can significantly affect trading outcomes.
Essential Features of a Telegram Crypto Trading Bot
A well-designed Telegram crypto trading bot should combine automated execution, wallet management, risk controls, security mechanisms, and real-time portfolio monitoring. Since users interact with the system through Telegram, the interface should also make complex trading functions accessible through simple commands and interactive buttons.
Essential Trading Features
Instant Trade Execution: Allow users to buy and sell supported digital assets directly through Telegram by connecting with decentralized exchanges (DEXs), centralized exchanges (CEXs), or both.
Token Sniping: Monitor newly launched tokens and liquidity events and automatically submit transactions when predefined conditions are met.
Limit and Market Orders: Support market orders for immediate execution and limit orders that trigger when an asset reaches a specified price.
Copy Trading: Enable users to follow selected wallet addresses or trading strategies and automatically replicate eligible transactions according to configured parameters.
Strategy Automation: Support automated strategies such as Dollar-Cost Averaging (DCA), grid trading, scheduled purchases, and other rule-based trading approaches.
Risk Management and Security
Stop-Loss and Take-Profit: Allow users to establish predefined exit conditions to automatically close trades when selected profit or loss thresholds are reached.
Token and Contract Risk Analysis: Analyze available indicators such as liquidity, contract permissions, trading restrictions, token taxes, and ownership structures to highlight potential risks before a transaction.
MEV Protection: Incorporate transaction-routing and execution mechanisms designed to reduce exposure to certain MEV-related threats, including frontrunning and sandwich attacks.
Secure Wallet Management: Protect wallet credentials and signing mechanisms through strong encryption, secure key handling, access controls, and appropriate separation between application data and sensitive wallet information.
Transaction Confirmation Controls: Give users visibility into transaction details before execution and allow configurable confirmation requirements for higher-value transactions.
User Experience and Portfolio Tracking
Real-Time Alerts: Notify users about completed transactions, price movements, triggered stop-loss or take-profit conditions, failed transactions, and other important account events.
Portfolio Tracking: Display token balances, transaction history, portfolio allocation, and performance information across supported wallets or networks.
Interactive Menus: Use Telegram’s inline buttons, menus, and commands to create a straightforward interface for buying, selling, checking balances, adjusting settings, and managing strategies.
Multi-Chain Support: Connect with multiple blockchain networks when required, allowing users to manage trading activity across supported ecosystems from a single Telegram interface.
Transaction History: Maintain an accessible record of executed trades, transaction hashes, fees, prices, and other relevant information.
Advanced Features for a Competitive Telegram Trading Bot
For a more sophisticated product, additional functionality can include:
Multi-wallet management
Custom trading strategies
Whale-wallet monitoring
Price and liquidity alerts
Gas-fee optimization
Referral and affiliate systems
Trading performance analytics
Admin dashboards
Subscription and premium features
API integrations
AI-assisted market analysis
The right feature set ultimately depends on whether the bot is designed for DEX trading, CEX automation, copy trading, portfolio management, or a combination of these functions. Security, transparent transaction handling, and user-controlled risk settings should remain central to the product architecture.
How to Build a Telegram Crypto Trading Bot for Indian Traders?
Building a Telegram crypto trading bot requires integrating Telegram with exchange APIs or blockchain networks and adding automated trading logic, wallet management, security, and risk controls.
1. Create the Telegram Bot
Use @Bot to create the bot, configure its username, and securely store the Telegram API token.
2. Choose the Technology Stack
Use technologies such as Python or Node.js for the backend, with PostgreSQL or MongoDB for data management and Redis for caching.
3. Integrate Exchanges and Blockchains
Connect with CEX APIs or DEX infrastructure to support trading. Blockchain RPCs and DEX aggregators can enable on-chain transactions.
4. Add Trading Features
Implement functions such as market and limit orders, DCA, grid trading, copy trading, stop-loss, take-profit, and automated trade execution.
5. Secure Wallets and APIs
Protect private keys and API credentials using encrypted storage, restricted permissions, secure authentication, and strong access controls.
6. Test and Deploy
Start with paper trading and security testing before deploying the bot on reliable cloud infrastructure for continuous operation.
7. Consider Indian Compliance
For India-focused bots, maintain accurate transaction records covering trades, fees, deposits, withdrawals, and transaction hashes to support applicable tax and reporting requirements.
In short, a successful Telegram trading bot combines a simple chat interface with secure trading infrastructure, automation, risk management, and reliable transaction tracking.
How Does a Telegram Trading Bot Make Money?
A Telegram trading bot can generate revenue through transaction fees, subscriptions, exchange partnerships, and promotional opportunities.
Key Revenue Models
Transaction Fees: Charge a small fee on trades or swaps executed through the bot.
Subscription Plans: Offer monthly or yearly plans with premium features such as advanced automation, priority execution, whale alerts, or enhanced analytics.
Affiliate & Referral Commissions: Earn commissions by referring users to supported exchanges, trading platforms, or blockchain services.
Sponsored Token Promotions: Allow legitimate crypto projects to promote tokens through featured listings, trending sections, or promotional placements.
Advertising Revenue: Generate additional income through eligible Telegram advertising and revenue-sharing opportunities.
A combination of transaction fees and premium subscriptions can provide a scalable monetization model while keeping basic trading functionality accessible to users.
Conclusion
Telegram crypto trading bots are becoming an efficient way to bring automated trading directly into a familiar messaging environment. From instant execution and copy trading to portfolio tracking, risk management, and AI-powered strategies, these bots can support a wide range of crypto trading use cases.
For businesses looking to launch a secure and scalable solution, choosing the right technology, integrations, trading logic, and monetization model is essential. Malgo can help transform your Telegram trading bot concept into a customized solution designed around your business goals and target market.
In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage.
We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal.
During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data to gain ongoing access to the victim’s account. With this stolen data, attackers can leverage the Telegram API to automatically pull chat logs, media files, and other information from the account.
The second component, Still Audio, is an implant for covert audio surveillance. It analyzes the incoming audio stream, automatically detects speech, records conversations, and sends the recordings to a command-and-control server.
In this article, we’ll look at the initial infection method, how the new Still Toolkit components are built, and the technical details of how they operate.
Kaspersky products detect this threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.
Background
Armored Likho’s malicious activity has been documented several times before: in November 2024, and in February and July 2026. The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure. At the same time, our research uncovered a number of new tools that point to the attackers expanding their capabilities.
Initial infection
The infection chain starts with an app that mimics a donation service. As of this writing, the app distribution method remains unknown. During our research, however, we obtained several samples posing as apps from different Russian foundations.
In reality, the app is a dropper. Its developers wrote it in Rust on top of the popular Tauri framework, and it has a graphical interface designed to deceive the user. After launch, it displays a login form that asks for a password, presumably one the attackers supplied.
The login form
After the user enters a valid password, they see a catalog of donatable items. The app pulls item and category information from orderapiserver[.]info through the public/categories and public/products endpoints. A clickable catalog makes the app look legitimate. While the user browses the items, the dropper quietly decrypts and launches the payload for the next stage in the background.
Our analysis shows that the mechanism for decrypting the payload and launching subsequent stages hasn’t changed since the February campaign. However, we found a new cyber-espionage toolkit – the Still Toolkit – made up of two components: Still Sync and Still Audio.
Still Sync
Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API.
Architecturally, Sync is an asynchronous application based on the Tokio library. It talks to the server over gRPC and serializes messages with FlatBuffers. It supports both HTTP and HTTPS as transport protocols; the URL of the command-and-control server determines which one it uses.
How it works
When Sync launches, the attackers set several environment variables. Before starting any malicious activity, the implant pulls configuration parameters from these:
STILL_SYNC_ADDR: the address of the command-and-control server. By default, this is https://tg4service[.]com:443.
STILL_SEND_PATH: the path to the tdata
STILL_TELEGRAM_PASSCODE: the password for decrypting the tdata folder, if Telegram data encryption is enabled on the victim’s device.
Sync also supports several command-line arguments:
--console: runs as a console application. If this parameter is absent, the implant creates a TReload service to keep running in the background.
--version: prints version information and exits.
--firefly: launches a trace thread that monitors the program’s operation. It writes error messages to a hidden file, bin, located in the same folder as the main executable.
--db: turns on debug mode with detailed logging.
Example Still Sync logs
Once it launches, the malware begins registering the device with the C2 server. To do this, Sync collects the following information about the victim’s system:
Motherboard serial number
CPU ID
System UUID
BIOS serial number
Computer domain name
The malware combines the collected data into a single string with a colon as the separator. It then hashes that string with SHA-256 and stores the resulting hash under the key sysmarker. Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm.
Sync then serializes a package containing all the collected information and the agent version, and sends it in a POST request to /still.rpc.Sync/RegisterMachine. The response contains a machine_id value, which Sync uses to identify itself in subsequent requests.
Once registration succeeds, Sync sends a POST request with the machine_id parameter to /still.rpc.Sync/GetMachineSettings. The server responds with the following settings:
enabled: triggers malicious activity on the infected device.
scan_portable: turns on extended scanning when searching for the tdata We’ll cover this feature in more detail below.
fetch_telegram: if this parameter is on, Sync attempts to log in to Telegram and extract data. We’ll cover this feature in more detail below.
download_channels: if this parameter is off, Sync skips channel dialogs when exfiltrating Telegram data.
These parameters have no default values, so Sync doesn’t perform any malicious actions until the registration and settings-retrieval processes both complete successfully.
Telegram data collection
Before stealing a Telegram session, Sync searches for the tdata folder, unless the STILL_SEND_PATH variable is already set. The list of search paths includes both standard and nonstandard directories, if the scan_portable option is turned on:
C:\Users\<username>\AppData\Roaming\Telegram Desktop\: the standard Telegram Desktop installation directory.
C:\Users\<username>\AppData\Local\Packages\<package_folder>\LocalCache\Roaming\: the installation directory for the Microsoft Store version. Sync identifies the package folder by a name that contains the string TelegramMessenge.
C:\: used for the extended search (if the scan_portable option is on).
Sync then sends a POST request with a list of files from the tdata folder to the /still.rpc.Sync/CheckFiles endpoint. The server responds with the following values:
snapshot_id: an identifier the server assigns to the current data snapshot.
present: a list of file paths that are already present on the server.
This lets the C2 server avoid re-receiving files it already has. In addition, if Sync can’t access files on disk through standard methods, it falls back on three mechanisms that abuse the SeBackupPrivilege privilege:
Opening files with the CreateFileW function using the FILE_FLAG_BACKUP_SEMANTICS parameter
Creating a backup copy through the Shadow Copy service and reading files from there
If the previous methods all fail, attempting to copy the file using the Robocopy utility in backup mode
Beyond stealing Telegram session data, Sync can carry out full-scale collection of user information from the messaging app. When the fetch_telegram option is on, it launches a separate thread that authenticates to the chat app using the previously obtained tdata. Once authentication succeeds, Sync gains access to the account data and sends the following collected information to the server:
User details, such as username, phone number, first and last name
Information about private chats, groups, or channels, such as chat name and ID, the member list, and so on
Dialogs from private chats, groups, and channels (if the download_channels option is on)
Media files under 250MB: photos, documents, stickers, and contacts
Still Audio
Still Audio is an audio surveillance implant written in Rust. Its main job is to analyze the incoming audio stream and start recording voice when certain conditions are met – we’ll cover those in the next section. Architecturally, Still Audio largely mirrors Sync and uses the same mechanisms for communicating with the C2 server.
On launch, Still Audio performs a sequence of actions:
It extracts libmp3lame.dll, a file stored inside the executable. This is a library used to encode audio data.
If the --console command-line argument is absent, the implant creates a service named auxhost, connects to it, and continues running in the background.
While running in the background, it creates a file, logfile.log, to write logs to.
Next, Still Audio retrieves the C2 server address. As with Sync, it stores the URL in an environment variable – in this case, STILL_AUDIO_SYNC_ADDR. If that variable isn’t set, it falls back to STILL_SYNC_ADDR, which shows the two modules are compatible with each other. If neither variable is set, it uses the default URL, https://srwinservice[.]com.
Still Audio also uses the Dead Drop Resolver technique as a fallback mechanism for obtaining the C2 address. If the current server stays unreachable for three days, the tool tries to pull the current C2 URL from a GitHub repository. In the sample under analysis, we found the following URL for the page containing C2 information: hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json
Encrypted C2 address inside the GitHub repository
The repository, a fork of a popular project, contains the server URL Base64-encoded and encrypted with the Blowfish algorithm in ECB mode, using the key 5c8e153228edd3c6cbf75684 (lowercase string). Older AquilaRAT samples use this exact same algorithm and key.
Once it obtains the current C2 address, the Audio module starts a registration process similar to Sync’s, but through a different endpoint:
/still.rpc.Audio/RegisterAudioMachine. Also, unlike Sync, Audio sends a list of available audio input devices along with the system information.
The server responds with settings for the implant:
machine_id: a unique identifier for the current device.
vad_threshold: the threshold value for the VAD (Voice Activity Detection) algorithm. Expressed as a decimal fraction, it represents a proportion of the maximum sound level the input device can pick up. Sound above this threshold counts as voice activity. The default vad_threshold is 02.
max_silence_duration: the number of audio samples with a VAD value below the set threshold after which the implant considers the recording finished.
max_buffer_size: the maximum buffer size for recorded audio data.
active_device: the name of the input device selected for recording, from the list of available devices.
The eavesdropping process
Still Audio works with raw audio samples it captures directly from the input device. To detect voice activity, it implements an algorithm based on Root Mean Square (RMS), a lightweight signal-processing method that distinguishes speech from silence by measuring the audio signal’s average power over time. The implant doesn’t rely on any third-party libraries here; it implements all the calculations itself.
The implant compares the calculated RMS value against the vad_threshold parameter. If RMS meets or exceeds this threshold, recording starts. To avoid losing the beginning of the recording, Still Audio uses a pre-buffer, a size-limited buffer that stores samples from just before the current recording moment. A sequence of max_silence_duration samples (320 by default) with RMS values below the threshold signals the end of the recording. For example, with a standard headset running at a 44.1kHz sampling rate, recording stops after roughly 7ms of silence.
Interestingly, the Audio module makes no attempt to hide its use of the microphone: its name shows up in Windows settings. In the sample we examined, the file was saved to disk as IntAudio.exe, and it appeared in the list of apps using the microphone as “Intel Audio”:
The malicious module in the list of apps using the microphone
Before sending recordings to the server, the implant uses the libmp3lame library to encode the raw audio samples. It sends the recording files via a POST request to /tgfrg, adding a Client-Id header containing the machine_id obtained during registration to identify the device.
Infrastructure
This campaign draws on a broad set of hosting providers and domains registered at different points in time, which suggests the attackers are trying to make their infrastructure harder to detect. We found no direct overlap in domains or IP addresses with the February campaign. Even so, the two infrastructures share some similarities:
They use the same hosting providers, with the ASNs 149440, 202448, and 215311.
Their domain names follow similar naming patterns that mimic Windows system services and update mechanisms.
Domain
IP address
Registration date
ASN
orderapiserver[.]info
187.127.153[.]38
April 18, 2026
47583
tg4service[.]com
159.198.37[.]74
October 4, 2025
22612
srwinservice[.]com
213.252.244[.]123
March 19, 2026
61272
screenserv[.]com
23.26.237[.]250
February 13, 2026
149440
windowserv[.]net
23.27.24[.]30
February 10, 2026
149440
managementapiservice[.]com
188.212.124[.]178
May 1, 2026
202448
service8date[.]com
145.223.69[.]143
January 13, 2026
215311
updateservs[.]com
145.223.68[.]66
December 23, 2025
215311
Victims
In this campaign, we’ve determined that the attackers’ primary targets are users in Russia. Most victims are private individuals, though the corporate sector, government organizations, IT companies, and educational institutions are also affected.
Attribution
This campaign has been using both new tools and malware families documented in BI.ZONE’s February report. While some components turned up for the first time, they show significant code-level overlap with malicious tools seen in earlier Armored Likho campaigns. Based on these overlaps, along with additional technical artifacts, we’re highly confident the Armored Likho group is behind the campaign. The overlaps we identified include:
Identical dropper architecture in the February and current campaigns, which includes the use of the Tauri library to build the graphical interface, a similar user-input handler, a payload with the ICRYPTMP header, and the same multi-part encryption format.
The same encryption algorithm and key used in AquilaRAT from the previous campaign and in the Still Audio module from the current campaign, both implementing the Dead Drop Resolver technique.
Identical logic for generating the sysmarker value in older AquilaRAT samples and in the Still toolkit from the current campaign. The algorithms match down to the PowerShell commands used to collect system information.
Substantial infrastructure overlap, which includes the hosting providers and domain-naming patterns described in the Infrastructure section.
Takeaways
The campaign described in this post shows Armored Likho’s toolkit evolving, with the group steadily expanding its cyber-espionage capabilities. Beyond the components we already knew about, the attackers rolled out new modules that let them not only access Telegram data but also conduct audio surveillance on victims. Together, these capabilities significantly widen the range of information attackers can collect in a single compromise.
One point deserves particular attention: the new tools form a cohesive set, sharing similar architecture, C2 communication mechanisms, and common implementation elements. This points to the group building out its own tool ecosystem, designed for long-term use and further expansion.
The emergence of new, specialized modules shows the attackers aren’t just trying to preserve their existing capabilities – they’re working to make intelligence-gathering more effective by controlling multiple communication channels at once.
Telegram's t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown.
WhatsApp is letting users reserve usernames before its 2026 launch, giving people a way to chat without sharing phone numbers. Here is how it works, why it matters, and the security limits to know