Angry Likho is a Russian-speaking espionage-focused APT cluster active since at least 2023 and tracked by some vendors as Sticky Werewolf. It is assessed as part of the broader Likho activity cluster and shows strong tradecraft overlap with Awaken Likho. The group primarily targets organizations in Russia and Belarus, with a particular focus on government institutions, large enterprises, and contractors. Angry Likho commonly gains initial access through targeted spearphishing emails in fluent Russian carrying malicious attachments. Observed delivery chains use self-extracting archives, shortcut files, heavily obfuscated command scripts, and AutoIt-based components to stage payloads. The group has employed anti-analysis checks, delayed execution, self-deletion, and process injection as part of its defense-evasion and post-compromise workflow. Activity observed in 2024 and 2025 indicates continued evolution of its tooling, including use of concealed Base64-encoded .NET payloads embedded in image files. A notable capability associated with Angry Likho is deployment of Lumma Stealer during targeted intrusions. In these operations, the malware was used to collect system information, installed software data, browser credentials, cookies, connection logs, payment-card-related data, and data from cryptocurrency wallets, authenticator applications, remote-access tools, and password managers. The group has been characterized by compact infrastructure, a limited but reusable implant set, and selective targeting of employees within larger organizations rather than broad indiscriminate campaigns. Known aliases and related naming include Sticky Werewolf, and the cluster is associated with the wider Likho ecosystem that also includes Awaken Likho. Available evidence supports classification of Angry Likho as a cyber-espionage actor rather than a ransomware or extortion operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
124 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage-focused APT group active against Russian organizations.
Named as an actor group associated with Lumma Stealer in the report, but not the primary focus of the actor discussion.
Referenced as a prominent threat actor group that has used the Lumma infostealer.
Targeted spear-phishing campaign against employees of large organizations, especially Russian government institutions and contractors, using self-extracting archives, obfuscated AutoIt-based implants, and Lumma stealer to steal credentials, banking data, and cryptowallet information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.