Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Awaken Likho

Also known as: Core Werewolf, PseudoGamaredon, the Newscaster Team, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, UNC4221, RedMike, OPERATOR PANDA

Description

Awaken Likho emerged in late 2021 and has since intensified operations against Russian government agencies and industrial enterprises—particularly within defense, energy, telecommunications, and finance. The adversary’s strategy hinges on low‑visibility deployment vectors: phishing emails with malicious LNK or Office attachments trigger PowerShell scripts that download DLLs embedding JSON configuration data and establish covert communication channels using MeshCentral and randomly generated domains for resilience. Recent analyses reveal a zero‑click attack chain leveraging a Windows Task Scheduler vulnerability (CVE‑2018‑0802) to elevate privileges, coupled with exploitation of legacy CVEs (CVE‑2017‑0199, CVE‑2017‑11882) via malicious RTF and Excel templates that deliver full‑featured backdoors such as VBShower, SmokeLoader, and a re‑engineered RomCom RAT. Awaken Likho demonstrates significant sophistication in its tooling portfolio. The group routinely deploys AutoIt scripts for stealthy installation, injects code into legitimate processes like explorer.exe, and utilizes widely available remote administration platforms (MeshCentral, AnyDesk, Remote Utilities) to facilitate lateral movement. Furthermore, they embed credential‑stealing modules within backdoors that target browsers and email clients. The attackers’ campaigns are marked by rapid evolution: each iteration adds new persistence mechanisms, expands C2 diversity via dynamic domain creation, and broadens its malicious payload library—often incorporating widely distributed commercial software (UltraVNC) and open-source frameworks (Cobalt Strike). This agility reflects a sophisticated adversary intent on maintaining operational continuity amid shifting defensive postures.

Goals & Targeting

Targeted Sectors

Government
Financial services
Manufacturing
Defense
Telecommunications
Energy
Pharmaceutical
Transportation
Education
Healthcare
Critical infrastructure
Construction
Food agriculture
Chemical
Retail
Maritime
Mining
Non profit
Aviation

Targeted Countries / Regions

RU
UA
IN
PK
DE
TR
BY
CN
US
KR
JP
IT
VN
BR
TW
SY
SA
AE
FR
CA
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 23 hours ago

Executive Summary

Awaken Likho is a highly adaptive state‑aligned APT group focused on espionage against Russian and allied entities across critical infrastructure sectors. The threat actors employ a blend of phishing, zero‑click exploitation, and remote‑management tools such as MeshCentral to maintain persistent footholds. Their latest malware iterations leverage AutoIt scripts and random domain generation for C2, indicating ongoing development and operational capability.

Goals & Targeting

Awaken Likho’s strategic objective centers on gathering actionable intelligence from high‑value targets that control critical infrastructure and national security assets. By targeting governmental, defense, energy, telecoms, finance, and industrial sectors across a wide geographic footprint—including Russia, Ukraine, the United States, China, India, and the Middle East—the group seeks to acquire intellectual property, state secrets, and proprietary technologies. The campaign appears driven by strategic geopolitical objectives tied to Russian state interests, prioritizing organizations that can influence regional power dynamics or provide insight into adversary capabilities.

Enhanced Description

Key Capabilities

  • Exploits web‑based remote management platform MeshCentral
  • Deploys AutoIt scripts for installation and configuration
  • Launches backdoors such as TokenBuoy via DLL delivery
  • Uses malicious LNK files in spam emails to trigger PowerShell commands
  • Extracts configuration data from embedded JSON within DLLs
  • Generates random domains for backup Command & Control servers
  • Zero‑click exploitation via shellcode (Task Scheduler vulnerability)
  • Sandbox escape using Task Scheduler vulnerability
  • Privilege escalation through undocumented RPC endpoint
  • Hidden PowerShell execution that downloads and runs RomCom RAT
  • Exploit of CVE-2018-0802 via malicious RTF template
  • Execution of HTA files and extraction of VBShower backdoor
  • Phishing emails with malicious attachments (RTF, Excel) for initial access
  • Use of malicious JavaScript downloaders in spear‑phishing campaigns
  • Remote access tool installation (AnyDesk, Remote Utilities)
  • Process injection into explorer.exe by SmokeLoader stager
  • Credential theft from browsers and email clients

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Defense Evasion
Privilege Escalation
Persistence
Credential Access

ATT&CK Techniques

T1566.001
T1204.002
T1105
T1059.003
T1071.004
T1068
T1203
T1055

Software / Tooling

AutoIt scripts
MeshCentral
TokenBuoy backdoor
MicrosoftStores.exe
UltraVNC agent
RomCom RAT
VBShower backdoor
PowerShower backdoor
VBCloud implant
AnyDesk
Remote Utilities
WasabiSeed
ScreenShotter
AHK Bot
Resident backdoor
Cobalt Strike
CSharp-Streamer-RAT
Rhadamanthys
Ande Loader
SmokeLoader

Campaigns & Victims

Awaken Likho typically launches campaigns from a single command‑and‑control hub that quickly expands through dynamically generated domains, allowing the group to persist even when individual nodes are taken down. The attacker frequently targets Russian governmental entities but has broadened its scope to include multinational corporations in sectors like finance and energy—mirroring the geopolitical focus of Russian state actors. Operations exhibit a high tempo: initial access via spear‑phishing or zero‑click mechanisms is followed by rapid lateral movement using remote‑administration tools (MeshCentral, AnyDesk). The group demonstrates consistent use of credential theft modules to harvest browser data and email credentials, often integrating the stolen information into future phishing vectors. Notable past operations include a December 2021 rollout targeting defense contractors via malicious LNK attachments and a 2023 campaign exploiting CVE‑2018‑0802 in RTF templates to release VBShower backdoors. Awaken Likho’s tactics reflect an evolving threat that balances stealth with aggressive data exfiltration, often employing fileless execution pathways such as PowerShell scripts executed from memory.

IOC Patterns

  • Suspicious LNK file attachments in spam emails
  • PowerShell commands that download DLLs
  • DLL installation from unknown source
  • Embedded JSON configuration files inside DLLs
  • Random domain generation for C2 backup servers
  • Usage of MeshCentral as remote control channel

Recommended Actions

  • Implement advanced email filtering to detect and block malicious LNK, RTF, Excel, ZIP attachments used in phishing campaigns.
  • Enforce application whitelisting and strict execution policies to prevent AutoIt scripts and unknown DLLs from running.
  • Restrict outbound traffic on uncommon remote‑management ports and monitor for unexpected MeshCentral connections.
  • Deploy endpoint detection that flags hidden PowerShell activity and process injection into explorer.exe. Monitor DNS logs for newly registered random domains and block recognized malicious C2 servers. Apply timely patches for Windows Vulnerabilities (Task Scheduler CVE‑2018‑0802, CVE‑2017‑0199, CVE‑2017‑11882) and enforce CVE vulnerability management. Deploy script signing enforcement to mitigate fileless PowerShell attacks.
  • Use behavioral analytics to detect credential‑stealing modules targeting browsers and email clients.
  • Maintain an up‑to‑date inventory of authorized remote administration tools (UltraVNC, AnyDesk, Remote Utilities) to identify unapproved installations.

Suggested Tags

phishing
malicious-lnk
powershell-execution
dll-download
backdoor
command-and-control
random-domain-generation
meshcentral
autit-scripts
ultravnc
remote-administration
apt
awaken-likho
state-sponsored
zero-click
credential-theft
fileless-execution
rtf-template-exploit

Confidence Assessment

The available intelligence indicates a reasonably thorough picture of Awaken Likho’s TTPs, including phishing vectors, zero‑click exploitation techniques, and use of MeshCentral. While the evidence is grounded in multiple vendor reports, some details—such as precise infrastructure attribution, internal operational tempo metrics, and full persistence mechanisms—remain partially inferred or missing. Consequently, confidence in the reported capabilities and toolset is high, but gaps persist regarding the extent of their in‑field command structure and future evolution plans.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT-C-35
  2. www.kaspersky.com — Cited by web research for: Global
  3. apt.etda.or.th — Cited by web research for: Jackal

Intel Summary

8

Techniques

56

Tools

0

Campaigns

20

IOCs

0

Observed Data

5

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
espionage
critical-infrastructure
russia
phishing
malicious-lnk
powershell-execution
dll-download
backdoor
command-and-control
random-domain-generation
meshcentral
autit-scripts
ultravnc
remote-administration
apt
awaken-likho
state-sponsored
zero-click
credential-theft
fileless-execution
rtf-template-exploit

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.