Also known as: Core Werewolf, PseudoGamaredon, the Newscaster Team, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, UNC4221, RedMike, OPERATOR PANDA
Awaken Likho emerged in late 2021 and has since intensified operations against Russian government agencies and industrial enterprises—particularly within defense, energy, telecommunications, and finance. The adversary’s strategy hinges on low‑visibility deployment vectors: phishing emails with malicious LNK or Office attachments trigger PowerShell scripts that download DLLs embedding JSON configuration data and establish covert communication channels using MeshCentral and randomly generated domains for resilience. Recent analyses reveal a zero‑click attack chain leveraging a Windows Task Scheduler vulnerability (CVE‑2018‑0802) to elevate privileges, coupled with exploitation of legacy CVEs (CVE‑2017‑0199, CVE‑2017‑11882) via malicious RTF and Excel templates that deliver full‑featured backdoors such as VBShower, SmokeLoader, and a re‑engineered RomCom RAT. Awaken Likho demonstrates significant sophistication in its tooling portfolio. The group routinely deploys AutoIt scripts for stealthy installation, injects code into legitimate processes like explorer.exe, and utilizes widely available remote administration platforms (MeshCentral, AnyDesk, Remote Utilities) to facilitate lateral movement. Furthermore, they embed credential‑stealing modules within backdoors that target browsers and email clients. The attackers’ campaigns are marked by rapid evolution: each iteration adds new persistence mechanisms, expands C2 diversity via dynamic domain creation, and broadens its malicious payload library—often incorporating widely distributed commercial software (UltraVNC) and open-source frameworks (Cobalt Strike). This agility reflects a sophisticated adversary intent on maintaining operational continuity amid shifting defensive postures.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Awaken Likho is a highly adaptive state‑aligned APT group focused on espionage against Russian and allied entities across critical infrastructure sectors. The threat actors employ a blend of phishing, zero‑click exploitation, and remote‑management tools such as MeshCentral to maintain persistent footholds. Their latest malware iterations leverage AutoIt scripts and random domain generation for C2, indicating ongoing development and operational capability.
Goals & Targeting
Awaken Likho’s strategic objective centers on gathering actionable intelligence from high‑value targets that control critical infrastructure and national security assets. By targeting governmental, defense, energy, telecoms, finance, and industrial sectors across a wide geographic footprint—including Russia, Ukraine, the United States, China, India, and the Middle East—the group seeks to acquire intellectual property, state secrets, and proprietary technologies. The campaign appears driven by strategic geopolitical objectives tied to Russian state interests, prioritizing organizations that can influence regional power dynamics or provide insight into adversary capabilities.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Awaken Likho typically launches campaigns from a single command‑and‑control hub that quickly expands through dynamically generated domains, allowing the group to persist even when individual nodes are taken down. The attacker frequently targets Russian governmental entities but has broadened its scope to include multinational corporations in sectors like finance and energy—mirroring the geopolitical focus of Russian state actors. Operations exhibit a high tempo: initial access via spear‑phishing or zero‑click mechanisms is followed by rapid lateral movement using remote‑administration tools (MeshCentral, AnyDesk). The group demonstrates consistent use of credential theft modules to harvest browser data and email credentials, often integrating the stolen information into future phishing vectors. Notable past operations include a December 2021 rollout targeting defense contractors via malicious LNK attachments and a 2023 campaign exploiting CVE‑2018‑0802 in RTF templates to release VBShower backdoors. Awaken Likho’s tactics reflect an evolving threat that balances stealth with aggressive data exfiltration, often employing fileless execution pathways such as PowerShell scripts executed from memory.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence indicates a reasonably thorough picture of Awaken Likho’s TTPs, including phishing vectors, zero‑click exploitation techniques, and use of MeshCentral. While the evidence is grounded in multiple vendor reports, some details—such as precise infrastructure attribution, internal operational tempo metrics, and full persistence mechanisms—remain partially inferred or missing. Consequently, confidence in the reported capabilities and toolset is high, but gaps persist regarding the extent of their in‑field command structure and future evolution plans.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
56
Tools
0
Campaigns
20
IOCs
0
Observed Data
5
Tactics