Also known as: Sticky Werewolf, Storm-0978, Tropical Scorpius, tracked as, MimiStick, is an advanced, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, APT-C-35, Origami Elephant, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, a Chinese-speaking threat actor, Deed RAT, SparrowDoor, CrowDoor, MASOL RAT for Linux, UNC2596, PhaseShifters, Scattered Spider, Brainworm, APT32, Core Werewolf, UNC4210, Asylum Ambuscade, Guildma, UNC4221, BERSERK BEAR, ALLANITE, CASTLE, DYMALLOY, TG-4192, Group 24, Havex, Koala Team, IRON LIBERTY, G0035, ATK6, ITG15, BROMINE, Blue Kraken, Ghost Blizzard, OPERATION HANGOVER, Donot Team, SectorE02, Orange Kala
Angry Likho is an advanced threat actor that has been active since 2023. Its operations focus on large organizations and government agencies in Russia and Belarus, but the group also targets other global sectors such as aviation, pharmaceuticals, finance, telecommunications, and critical infrastructure. The group deploys a mix of spear‑phishing emails with malicious RAR archives and zero‑click phishing that leverages publicly disclosed Windows CVEs (e.g., CVE‑2025‑29824, CVE‑2023‑46805, CVE‑2024‑21887). Once inside the target network, Angry Likho installs a range of proprietary backdoors and remote access trojans including Deed RAT, PipeMagic, GHOSTSPIDER, SNAPPYBEE (Deed RAT variant), SparrowDoor, CrowDoor, MASOL RAT Linux, DEMODEX rootkit, NeoReGeorg, frpc, and Cobalt Strike. The actor uses sophisticated dropper techniques such as trojanized installers derived from Rufus or Microsoft Help Index files, DLL hijacking against legitimate executables (e.g., Google Chrome update), and shellcode decryption via custom C# loaders. Additionally, the group exploits LOLBins for reconnaissance and lateral movement while running hidden PowerShell scripts to execute remote code. At the exfiltration stage, Angry Likho typically drops the Lumma Stealer or similar infostealers that harvest user credentials, cryptocurrency wallet files, and other sensitive artifacts before encrypting and transmitting them back to command‑and‑control infrastructure. The group’s toolkit demonstrates a blend of legacy APT capabilities with modern exploit techniques. Overall, Angry Likho exhibits an espionage‑oriented profile combined with clear financial motivation, targeting high-value assets across multiple industries while maintaining persistence through diverse backdoor families.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Angry Likho, also known as Sticky Werewolf and Core Werewolf, is a financially motivated APT that has operated since early 2023 primarily against large Russian enterprises and government agencies. The group employs spear‑phishing attachments and zero‑click CVE exploitation to deliver a suite of persistent backdoors and infostealers such as Lumma Stealer, while collecting credentials, cryptocurrency wallets, and highly sensitive data from aviation, pharmaceutical, and critical infrastructure sectors.
Goals & Targeting
Angry Likho appears to pursue dual objectives: 1) strategic espionage on state‑controlled or large‑scale entities in Russia and Belarus, especially those handling aviation, defense, and pharmaceuticals; and 2) financial exploitation via credential theft and cryptocurrency wallet harvesting. The group's targeting breadth—encompassing telecommunications, energy, manufacturing, and critical infrastructure—reflects a flexible approach designed to profit from both high-value information assets and monetary gains through illicit financial channels.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since early 2023 Angry Likho has maintained a steady operational tempo, conducting targeted spear‑phishing campaigns against large Russian entities and government bodies. The group blends classic attachment‑based delivery with sophisticated zero‑click exploitation of publicly known CVEs to bypass traditional security controls. Victim types span high‑value sectors including aviation, pharmaceuticals, telecommunications, defense, and critical infrastructure, while also penetrating global finance and energy organizations. Notable past operations have included the deployment of Lumma Stealer for credential harvesting and the use of DLL hijacking to gain persistence in corporate networks.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
7
Techniques
50
Tools
0
Campaigns
61
IOCs
0
Observed Data
4
Tactics