Angry Likho

THREAT ACTOR PROFILE

Angry Likho

Angry Likho

Angry Likho

Angry Likho is a Russian-speaking espionage group active since 2023 that targets large organizations, government agencies and contractors in Russia and Belarus. It relies on phishing with 7-Zip self-extracting archives disguised as PDFs, and it has moved from off-the-shelf stealers like Lumma toward custom backdoors such as CoreRAT, TokenBuoy and TokenBuoySH.

Russia-linked

Government / Defense

First seen

2023

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Angry Likho, Sticky Werewolf and the Werewolf cluster

Angry Likho is tracked under several vendor names tied to the "Werewolf" and "Likho" naming schemes. It maps to one entry among the Russia-aligned actors we profile, and its phishing-led operations against regional targets sit near actors like Gamaredon.

-

-

-

GROUP PROFILE

Phishing-led espionage on Russian and Belarusian targets

Angry Likho runs targeted espionage against Russian-speaking organizations. The group is likely composed of native Russian speakers and focuses on government bodies, defense industry and large corporations, consistent with intelligence collection rather than financial gain.

Our record places its origin as Russia-linked and ties it to espionage against government and defense targets. Kaspersky and BI.ZONE have tracked overlapping clusters (Angry Likho, Awaken Likho, Core Werewolf) since 2023.

The group's tradecraft centers on Telegram and email phishing with 7-Zip SFX archives and Rust droppers carrying government and military-themed PDF decoys, then deploys remote access tools and custom backdoors.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

ATTACK LIFECYCLE

SFX archives and decoy PDFs into custom backdoors

The stages below come from Angry Likho, Awaken Likho and Core Werewolf activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

CoreRAT, TokenBuoy and Lumma Stealer

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through phishing, not CVE exploitation

Angry Likho's intrusions in our records rely on phishing with SFX archives and decoy documents rather than on exploiting software vulnerabilities, and our records list no exploited CVEs for the group. Detection should focus on the 7-Zip SFX and Rust-dropper delivery chain and the CoreRAT and TokenBuoy backdoors.

Angry Likho

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Angry Likho

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Angry Likho

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Angry Likho

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

CoreRAT and the TokenBuoy backdoors

Recent reporting tracks the group's move to custom tooling.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Angry Likho

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Angry Likho

IOC set, full IP, host and hash history.