Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mythic Likho

Also known as: Arcane Werewolf, Storm-0978, Tropical Scorpius, Smoke Sandstorm, TA455, aviation, tracked as, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Yellow Liderc, Tortoiseshell, defense industries, LuoYu, foreign entities, Qilin, file transfer tools, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Imperial Kitten, 0ktapus, UNC2596, Blue Echidna, GOFFEE, Fluffy Wolf, CASCADE PANDA, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, CVE-2025-14500, UAC-0252, deployed the DEAFTICKK backdoor, the SALATSTEALER infostealer, the SHADOWSNIFF open-source infostealer, CVE-2026-21385, FX, has passed away, GhostWeaver, Kimsuky, CopyCop, Doppelganger, CVE-2025-24200, CVE-2025-0108, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, FROZENBARENTS, UAC-0113, UAC-0082, SANDWORM RELIC

Description

Mythic Likho (aliases Arcane Werewolf, Storm‑0978, among others) is believed to be an advanced persistent threat employing a multi‑stage attack chain that begins with personalized spear‑phishing emails. The emails often masquerade as legitimate update notifications or internal documents and redirect victims through a Cloudflare‑style page that exploits Chrome CVE‑2018‑6065; if the exploit fails, a decoy site is served while hardcoded 64‑bit shellcode in the malicious JavaScript contacts a command‑and‑control server to download an encrypted payload. The actor also leverages known software vulnerabilities for initial access. A prominent campaign exploited a WinRAR path traversal zero‑day (CVE‑2025‑8088) that uses alternate data streams to hide backdoors such as SnipBot, RustyClaw and the Mythic agent behind seemingly innocuous ZIP archives. In addition, Cisco IOS Smart Install vulnerability CVE‑2018‑0171 and WinRAR CVEs (CVE‑2025‑6218/8088) have been cited in other operations. Beyond initial acquisition, Mythic Likho deploys persistence mechanisms that include firmware implants via Synful Knock and SNMP tooling. The actor frequently injects malicious DLLs into Windows Defender using DllPath manipulation, delivers reverse shells through modified XPS Viewer executables, and uses .NET assemblies to download secondary components in memory. A notable feature of this threat actor is the use of digitally signed binaries from SSL.com certificates to masquerade as legitimate code—a strategy that enhances evasion. Their targeted sectors span defense, manufacturing, financial services, logistics, energy, telecom, transportation and other high‑value industries across a global footprint (US, EU, Asia, Canada). While both espionage and monetary objectives are evident, the precise balance remains unclear.

Goals & Targeting

Targeted Sectors

Financial services
Manufacturing
Defense
Government
Telecommunications
Transportation
Critical infrastructure
Energy
Healthcare
Education
Aerospace
Retail
Media
Food agriculture
Aviation
Construction
Oil gas
Pharmaceutical
Entertainment
Utilities
Chemical
Maritime
Mining
Information technology
Legal services
Hospitality
Gaming
Nuclear

Targeted Countries / Regions

US
RU
IR
CN
BY
UA
IL
CA
GB
BR
TW
KZ
EG
DE
SG
VN
TR
PK
IT
FR
IN
MX
JP
AU
KP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Mythic Likho, also known as Arcane Werewolf or Storm‑0978, is a highly sophisticated threat actor targeting defense, manufacturing, financial services and other critical sectors worldwide. The group combines spear‑phishing, drive‑by exploitation of browser and WinRAR zero‑day vulnerabilities, and heavily obfuscated backdoor payloads to gain initial access and establish persistence. Their operations indicate both espionage motives—evident from targeted credential theft—and a clear financial‑gain component through ransomware or data exfiltration.

Goals & Targeting

Mythic Likho’s strategic objective appears to combine state‑level intelligence collection with opportunistic financial gain. By compromising defense and manufacturing firms, the actor can exfiltrate sensitive design data or operational procedures for geopolitical advantage while also harvesting credentials or leveraging ransomware for direct payouts. The group favors highly technical and well-resourced targets that operate in regulated industries—government agencies, utility operators, aerospace manufacturers—and selects victims wherever a sophisticated exploitation chain is feasible.

Enhanced Description

Key Capabilities

  • Spearfishing emails with personalized lures
  • Spear‑phishing attachments using malicious RAR files
  • Drive‑by exploitation of browser vulnerability CVE-2018-6065 via Cloudflare-mimicking redirect
  • Redirection chain with a fake Cloudflare page and JavaScript loader
  • Hardcoded 64-bit shellcode embedded in web pages to download encrypted payloads
  • Decryption and execution of the downloaded binary
  • Deployment of backdoor implants such as SnipBot, RustyClaw, and Mythic agent
  • WinRAR path traversal zero-day (CVE-2025-8088) via alternate data streams to hide backdoors
  • Exploitation of Cisco Smart Install CVE-2018-0171 and WinRAR CVEs (CVE-2025-6218/8088) for initial access
  • Execution of reverse shells from modified XPS Viewer executables
  • DLL hijacking/injection into Windows Defender using DllPath manipulation
  • Browser credential theft via MiniBrowse stealer
  • Permanently maintaining persistence through firmware implants (Synful Knock) and SNMP tooling
  • Distributing signed malicious binaries using SSL.com certificates to masquerade as legitimate code
  • .NET executable payloads that download secondary components in memory

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Credential Access
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1566.001
T1189
T1078
T1105
T1140
T1068
T1055
T1555.003

Software / Tooling

loki 2.1 implant
CHINACHOPPER (Malware Family)
Mythic agent
SnipBot variant
RustyClaw
Static Tundra
SYNful Knock firmware implant
SNMP tooling
Paper Werewolf/GOFFEE
WinRAR
.NET executables
Nimbus Manticore
MiniJunk backdoor
MiniBrowse stealer
Minibike

Campaigns & Victims

Mythic Likho has executed a series of highly technical campaigns that exploit multiple zero‑day vulnerabilities, leverage sophisticated spear‑phishing lures, and deploy stealthy backdoors to high‑value targets in defense, finance and manufacturing. The actor’s operations exhibit consistent use of Chrome CVE‑2018‑6065 drive‑by exploitation combined with a Cloudflare‑style redirection chain, followed by the delivery of encrypted payloads that run via hardcoded shellcode. Concurrent campaigns have employed WinRAR path traversal zero‑day (CVE‑2025‑8088) to hide backdoors for the first time in 2024, affecting organizations across Europe and Canada. Operational tempo is measured in bursts—typically spanning weeks to months with periods of inactivity—and indicates a well‑resourced threat actor capable of adapting rapidly to new patches or defensive measures. Victim types range from government agencies to critical infrastructure operators; notable past operations include compromise attempts on Russian manufacturing firms, U.S. financial services institutions and European aerospace contractors. The actor’s persistence tactics extend beyond software exploits: firmware implants via Synful Knock enable long‑term footholds, and the use of DLL hijacking into system components such as Windows Defender provides stealthy lateral movement opportunities. These patterns suggest a strategic intent to maintain continuous access while conducting both espionage and monetization activities.

IOC Patterns

  • Phishing emails with personalized lures
  • Inverted software update or internal documents
  • Redirection to a Cloudflare-mimicking site
  • Malicious JavaScript files loaded from URLs
  • Exploit of Chrome CVE-2018-6065
  • Hardcoded 64-bit shellcode embedded in the page
  • Decryption and execution of downloaded binary
  • WinRAR path traversal CVE‑2025‑8088 via alternate data streams to hide backdoor
  • Delivery of backdoors such as SnipBot, RustyClaw, Mythic agent
  • CVE-2018-0171 vulnerability in Smart Install feature of Cisco IOS
  • CVE-2025-6218 WinRAR vulnerability exploit used
  • CVE-2025-8088 zero-day WinRAR vulnerability
  • Spear‑phishing email with RAR attachment and fake ministry documents
  • Malicious XPS Viewer executable containing embedded reverse shell shellcode
  • Directory traversal exploit writing files outside the target directory
  • DLL hijacking via manipulated DllPath to load malicious DLLs into Windows Defender
  • Signed binaries using SSL.com certificates masquerading as legitimate code
  • Reverse shell connection from victim to attacker C2 server

Recommended Actions

  • Patch Chrome browser to mitigate CVE‑2018‑6065 before the next vulnerable release.
  • Apply and maintain updates for WinRAR, prioritizing fixes for CVE-2025-8088 (path traversal) and CVE-2025-6218 zero-day vulnerabilities.
  • Deploy advanced email filtering and spear-phishing detection to block malicious links or attachments from unknown senders.
  • Enable web-filtering and sandbox analysis to detect drive-by exploitation attempts and remotely loaded JavaScript payloads.
  • Monitor endpoints for atypical shellcode execution, unauthorized file writes and hidden files in archive extraction; avoid using alternate data streams when extracting archives.
  • Harden Cisco IOS devices by disabling or patching Smart Install feature to mitigate CVE-2018-0171 attacks.
  • Log and inspect DLL loading paths, especially for Windows Defender and other system binaries, to detect hijacking via DllPath manipulation.
  • Monitor network traffic for reverse shell connections and command-and-control patterns such as inbound C2 requests over uncommon ports or protocols.
  • Verify code signatures of executable files and track the use of legitimate certificates from SSL.com that may be abused by malware authors.
  • Implement an ongoing threat-hunting program focused on identifying persistence via firmware implants and SNMP-based tools.

Suggested Tags

SpearPhishing
DriveByCompromise
BrowserVulnerability
C2Download
BackdoorDelivery
AltDataStreams
IndustrialEspionage
FinancialCybercrime
ZeroDayExploit
TargetedSectorDefense
APT
Targeted Phishing
CVE Exploit
Firmware Persistence
DLL Injection
Credential Theft from Browser
Reverse Shell
WinRAR Exploit
MiniJunk Backdoor
MiniBrowse Stealer

Confidence Assessment

The confidence in the core TTPs—spear‑phishing, drive‑by exploitation of Chrome CVE‑2018‑6065, WinRAR zero‑day path traversal (CVE‑2025‑8088), and backdoor deployment—is high based on multiple independent observations. Attribution remains tentative due to overlapping aliases and limited conclusive evidence linking all operations to a single nation-state actor; however the sophistication of exploitation and persistence mechanisms strongly suggests an advanced persistent threat with potential state sponsorship. Unknowns persist around long-term operational tempo, exact financial impact, and whether the motive leans more toward espionage or monetization.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. ics-cert.kaspersky.com — Cited by web research for: Crouching Yeti
  3. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  4. risky.biz — Cited by web research for: CVE-2025-14500
  5. www.risky.biz — Cited by web research for: CVE-2025-21391
  6. https://www.kaspersky.com/ — Cited by AI analysis.
  7. https://nvd.nist.gov/vuln/detail/CVE-2018-6065 — Cited by AI analysis.
  8. https://nvd.nist.gov/vuln/detail/CVE-2018-0171 — Cited by AI analysis.
  9. https://nvd.nist.gov/vuln/detail/CVE-2025-8088 — Cited by AI analysis.
  10. https://nvd.nist.gov/vuln/detail/CVE-2025-6218 — Cited by AI analysis.

Intel Summary

8

Techniques

61

Tools

0

Campaigns

39

IOCs

0

Observed Data

5

Tactics

Tags

Phishing
Backdoor / C2
APT
Industrial espionage
Manufacturing sector targeting
SpearPhishing
DriveByCompromise
BrowserVulnerability
C2Download
BackdoorDelivery
AltDataStreams
IndustrialEspionage
FinancialCybercrime
ZeroDayExploit
TargetedSectorDefense
Targeted Phishing
CVE Exploit
Firmware Persistence
DLL Injection
Credential Theft from Browser
Reverse Shell
WinRAR Exploit
MiniJunk Backdoor
MiniBrowse Stealer

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.