Also known as: Arcane Werewolf, Storm-0978, Tropical Scorpius, Smoke Sandstorm, TA455, aviation, tracked as, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Yellow Liderc, Tortoiseshell, defense industries, LuoYu, foreign entities, Qilin, file transfer tools, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Imperial Kitten, 0ktapus, UNC2596, Blue Echidna, GOFFEE, Fluffy Wolf, CASCADE PANDA, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, CVE-2025-14500, UAC-0252, deployed the DEAFTICKK backdoor, the SALATSTEALER infostealer, the SHADOWSNIFF open-source infostealer, CVE-2026-21385, FX, has passed away, GhostWeaver, Kimsuky, CopyCop, Doppelganger, CVE-2025-24200, CVE-2025-0108, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, FROZENBARENTS, UAC-0113, UAC-0082, SANDWORM RELIC
Mythic Likho (aliases Arcane Werewolf, Storm‑0978, among others) is believed to be an advanced persistent threat employing a multi‑stage attack chain that begins with personalized spear‑phishing emails. The emails often masquerade as legitimate update notifications or internal documents and redirect victims through a Cloudflare‑style page that exploits Chrome CVE‑2018‑6065; if the exploit fails, a decoy site is served while hardcoded 64‑bit shellcode in the malicious JavaScript contacts a command‑and‑control server to download an encrypted payload. The actor also leverages known software vulnerabilities for initial access. A prominent campaign exploited a WinRAR path traversal zero‑day (CVE‑2025‑8088) that uses alternate data streams to hide backdoors such as SnipBot, RustyClaw and the Mythic agent behind seemingly innocuous ZIP archives. In addition, Cisco IOS Smart Install vulnerability CVE‑2018‑0171 and WinRAR CVEs (CVE‑2025‑6218/8088) have been cited in other operations. Beyond initial acquisition, Mythic Likho deploys persistence mechanisms that include firmware implants via Synful Knock and SNMP tooling. The actor frequently injects malicious DLLs into Windows Defender using DllPath manipulation, delivers reverse shells through modified XPS Viewer executables, and uses .NET assemblies to download secondary components in memory. A notable feature of this threat actor is the use of digitally signed binaries from SSL.com certificates to masquerade as legitimate code—a strategy that enhances evasion. Their targeted sectors span defense, manufacturing, financial services, logistics, energy, telecom, transportation and other high‑value industries across a global footprint (US, EU, Asia, Canada). While both espionage and monetary objectives are evident, the precise balance remains unclear.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Mythic Likho, also known as Arcane Werewolf or Storm‑0978, is a highly sophisticated threat actor targeting defense, manufacturing, financial services and other critical sectors worldwide. The group combines spear‑phishing, drive‑by exploitation of browser and WinRAR zero‑day vulnerabilities, and heavily obfuscated backdoor payloads to gain initial access and establish persistence. Their operations indicate both espionage motives—evident from targeted credential theft—and a clear financial‑gain component through ransomware or data exfiltration.
Goals & Targeting
Mythic Likho’s strategic objective appears to combine state‑level intelligence collection with opportunistic financial gain. By compromising defense and manufacturing firms, the actor can exfiltrate sensitive design data or operational procedures for geopolitical advantage while also harvesting credentials or leveraging ransomware for direct payouts. The group favors highly technical and well-resourced targets that operate in regulated industries—government agencies, utility operators, aerospace manufacturers—and selects victims wherever a sophisticated exploitation chain is feasible.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Mythic Likho has executed a series of highly technical campaigns that exploit multiple zero‑day vulnerabilities, leverage sophisticated spear‑phishing lures, and deploy stealthy backdoors to high‑value targets in defense, finance and manufacturing. The actor’s operations exhibit consistent use of Chrome CVE‑2018‑6065 drive‑by exploitation combined with a Cloudflare‑style redirection chain, followed by the delivery of encrypted payloads that run via hardcoded shellcode. Concurrent campaigns have employed WinRAR path traversal zero‑day (CVE‑2025‑8088) to hide backdoors for the first time in 2024, affecting organizations across Europe and Canada. Operational tempo is measured in bursts—typically spanning weeks to months with periods of inactivity—and indicates a well‑resourced threat actor capable of adapting rapidly to new patches or defensive measures. Victim types range from government agencies to critical infrastructure operators; notable past operations include compromise attempts on Russian manufacturing firms, U.S. financial services institutions and European aerospace contractors. The actor’s persistence tactics extend beyond software exploits: firmware implants via Synful Knock enable long‑term footholds, and the use of DLL hijacking into system components such as Windows Defender provides stealthy lateral movement opportunities. These patterns suggest a strategic intent to maintain continuous access while conducting both espionage and monetization activities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core TTPs—spear‑phishing, drive‑by exploitation of Chrome CVE‑2018‑6065, WinRAR zero‑day path traversal (CVE‑2025‑8088), and backdoor deployment—is high based on multiple independent observations. Attribution remains tentative due to overlapping aliases and limited conclusive evidence linking all operations to a single nation-state actor; however the sophistication of exploitation and persistence mechanisms strongly suggests an advanced persistent threat with potential state sponsorship. Unknowns persist around long-term operational tempo, exact financial impact, and whether the motive leans more toward espionage or monetization.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
61
Tools
0
Campaigns
39
IOCs
0
Observed Data
5
Tactics