Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Angry Likho

Also known as: Sticky Werewolf, Storm-0978, Tropical Scorpius, tracked as, MimiStick, is an advanced, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, APT-C-35, Origami Elephant, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, a Chinese-speaking threat actor, Deed RAT, SparrowDoor, CrowDoor, MASOL RAT for Linux, UNC2596, PhaseShifters, Scattered Spider, Brainworm, APT32, Core Werewolf, UNC4210, Asylum Ambuscade, Guildma, UNC4221, BERSERK BEAR, ALLANITE, CASTLE, DYMALLOY, TG-4192, Group 24, Havex, Koala Team, IRON LIBERTY, G0035, ATK6, ITG15, BROMINE, Blue Kraken, Ghost Blizzard, OPERATION HANGOVER, Donot Team, SectorE02, Orange Kala

Description

Angry Likho is an advanced threat actor that has been active since 2023. Its operations focus on large organizations and government agencies in Russia and Belarus, but the group also targets other global sectors such as aviation, pharmaceuticals, finance, telecommunications, and critical infrastructure. The group deploys a mix of spear‑phishing emails with malicious RAR archives and zero‑click phishing that leverages publicly disclosed Windows CVEs (e.g., CVE‑2025‑29824, CVE‑2023‑46805, CVE‑2024‑21887). Once inside the target network, Angry Likho installs a range of proprietary backdoors and remote access trojans including Deed RAT, PipeMagic, GHOSTSPIDER, SNAPPYBEE (Deed RAT variant), SparrowDoor, CrowDoor, MASOL RAT Linux, DEMODEX rootkit, NeoReGeorg, frpc, and Cobalt Strike. The actor uses sophisticated dropper techniques such as trojanized installers derived from Rufus or Microsoft Help Index files, DLL hijacking against legitimate executables (e.g., Google Chrome update), and shellcode decryption via custom C# loaders. Additionally, the group exploits LOLBins for reconnaissance and lateral movement while running hidden PowerShell scripts to execute remote code. At the exfiltration stage, Angry Likho typically drops the Lumma Stealer or similar infostealers that harvest user credentials, cryptocurrency wallet files, and other sensitive artifacts before encrypting and transmitting them back to command‑and‑control infrastructure. The group’s toolkit demonstrates a blend of legacy APT capabilities with modern exploit techniques. Overall, Angry Likho exhibits an espionage‑oriented profile combined with clear financial motivation, targeting high-value assets across multiple industries while maintaining persistence through diverse backdoor families.

Goals & Targeting

Targeted Sectors

Financial services
Telecommunications
Manufacturing
Government
Defense
Transportation
Healthcare
Education
Retail
Construction
Energy
Critical infrastructure
Pharmaceutical
Aerospace
Aviation
Food agriculture
Mining
Oil gas
Media
Entertainment
Chemical
Legal services
Utilities
Hospitality
Maritime
Non profit

Targeted Countries / Regions

RU
BY
US
UA
BR
TR
CN
TW
VN
IN
PK
KZ
CA
JP
DE
SG
AU
KR
IT
GB
EG
SA
AE
FR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Angry Likho, also known as Sticky Werewolf and Core Werewolf, is a financially motivated APT that has operated since early 2023 primarily against large Russian enterprises and government agencies. The group employs spear‑phishing attachments and zero‑click CVE exploitation to deliver a suite of persistent backdoors and infostealers such as Lumma Stealer, while collecting credentials, cryptocurrency wallets, and highly sensitive data from aviation, pharmaceutical, and critical infrastructure sectors.

Goals & Targeting

Angry Likho appears to pursue dual objectives: 1) strategic espionage on state‑controlled or large‑scale entities in Russia and Belarus, especially those handling aviation, defense, and pharmaceuticals; and 2) financial exploitation via credential theft and cryptocurrency wallet harvesting. The group's targeting breadth—encompassing telecommunications, energy, manufacturing, and critical infrastructure—reflects a flexible approach designed to profit from both high-value information assets and monetary gains through illicit financial channels.

Enhanced Description

Key Capabilities

  • Persistent backdoor deployment
  • Exploitation of public vulnerabilities (CVE‑2025‑29824, CVE‑2023‑46805, CVE‑2024‑21887, CVE‑2023‑48788, CVE‑2022‑3236, CVE‑2021‑26855, CVE‑2021‑26857-6858, CVE‑2021‑27065)
  • Use of fake application bait (e.g., fake ChatGPT client)
  • Trojanized installer loaders via Rufus and Microsoft Help Index File
  • DLL hijacking into legitimate executables such as Google Chrome update
  • Shellcode decryption via custom C# loaders
  • Zero‑click phishing through browser and Windows CVEs with Task Scheduler escape
  • Use of LOLBins for reconnaissance and lateral movement
  • Deployment of specialized backdoors and RATs (PipeMagic, GHOSTSPIDER, SNAPPYBEE/Deed RAT, SparrowDoor, CrowDoor, MASOL RAT Linux, DEMODEX rootkit, NeoReGeorg, frpc, Cobalt Strike)
  • Execution of hidden PowerShell for remote code execution

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1566.001
T1566.003
T1190
T1068
T1086
T1059
T1106

Software / Tooling

Lumma Stealer
Deed RAT
PipeMagic
GHOSTSPIDER
SNAPPYBEE
SparrowDoor
CrowDoor
MASOL RAT Linux
DEMODEX Rootkit
NeoReGeorg
frpc
Cobalt Strike
Tomiris
PlugX
MetaStealer
PhantomCore

Campaigns & Victims

Since early 2023 Angry Likho has maintained a steady operational tempo, conducting targeted spear‑phishing campaigns against large Russian entities and government bodies. The group blends classic attachment‑based delivery with sophisticated zero‑click exploitation of publicly known CVEs to bypass traditional security controls. Victim types span high‑value sectors including aviation, pharmaceuticals, telecommunications, defense, and critical infrastructure, while also penetrating global finance and energy organizations. Notable past operations have included the deployment of Lumma Stealer for credential harvesting and the use of DLL hijacking to gain persistence in corporate networks.

IOC Patterns

  • file
  • domain
  • email
  • ip-v4

Recommended Actions

  • Implement comprehensive email filtering that blocks ZIP and RAR attachments or requires additional verification for large attachments.
  • Apply timely patching for all publicly disclosed CVEs, especially those exploited by Angry Likho (e.g., CVE‑2025‑29824).
  • Enable PowerShell Constrained Language mode and monitor for hidden PowerShell processes via endpoint detection tools.
  • Enforce application whitelisting and code integrity enforcement to mitigate DLL hijacking attempts on critical binaries like Google Chrome. Use network segmentation and least privilege controls to limit lateral movement opportunities.
  • Deploy advanced threat protection solutions to detect known backdoor families (Deed RAT, PipeMagic, Cobalt Strike).
  • Require MFA for privileged accounts to reduce credential theft impact. Regularly conduct network traffic analysis to spot anomalous outbound connections to known command‑and‑control endpoints. Provide security awareness training focused on spear‑phishing and zero‑click tactics.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. ics-cert.kaspersky.com — Cited by web research for: APT-C-35
  3. apt.etda.or.th — Cited by web research for: Cobalt

Intel Summary

7

Techniques

50

Tools

0

Campaigns

61

IOCs

0

Observed Data

4

Tactics

Tags

APT
Healthcare Targeting
Phishing
Data Exfiltration
Government Targeting
Espionage
Russia-linked
Belarus
Government targeting
Spear-phishing
Data exfiltration

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.