
Findings and evidence
Kaspersky identifies a Rust-based toolkit in an Armored Likho campaign. The reported components target Telegram session material and audio collection, extending the capabilities documented in earlier investigations of the group.
Why it matters
Messaging-account investigations may require endpoint and account evidence together. Record the device state, collection scope and session history, and protect sensitive communications in the resulting case material.
Scope and limits
The report’s attribution draws on campaign overlap. Finding a Telegram data directory or a Rust executable alone does not support that attribution or establish surveillance.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-08-13. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.