Mythic Likho Uses Sophisticated Malware and Social Engineering to Attack Russian Critical Infrastructure

· Original article ↗

Summary

Positive Technologies researchers detail Mythic Likho’s phishing, custom loaders and Loki backdoor, credential theft, data exfiltration, and LockBit deployment against Russian organizations, and report evidence of links to (Ex)Cobalt.

Key points

  • The group targets Russian organizations, particularly in mechanical engineering, mining, and manufacturing, using tailored phishing and carefully prepared social-engineering cover stories.
  • Phishing messages may first build trust before delivering malicious links; payloads are disguised in RAR or ISO archives with SCR or LNK loaders and decoy documents.
  • Custom HuLoader and ReflectPulse loaders deliver the Loki backdoor; the group also uses Merlin and a range of tools for credential theft, reconnaissance, and lateral movement.
  • Attackers establish persistence with Windows registry changes, new local accounts, and SSH keys; they disable antivirus software and use tunnels to move through compromised networks.
  • The group collects and exfiltrates data through Rclone or Loki, then may deploy LockBit ransomware, format RAID arrays, and remove recovery tools.
  • Investigators found artifacts suggesting Mythic Likho may collaborate with or share tools with (Ex)Cobalt; they say evidence is insufficient to link the group to XDSpy.

Article Details

Attack Vectors
  • Targeted phishing emails impersonate business partners, government agencies, media outlets, and cloud storage services. Initial messages may establish trust before subsequent messages deliver malicious download links.
  • Payloads are delivered from compromised organizational websites, phishing domains, and cloud storage accounts in ISO files or RAR archives containing SCR or LNK loaders and decoy documents.
  • LNK commands use delayed environment-variable expansion to replace apparent local IP addresses with malicious domains at runtime, download subsequent stages, and execute them.
  • Some investigated intrusions used SSH access previously established by (Ex)Cobalt operators.
  • Stolen local credentials, remote command-execution utilities, and mounted SMB shares enable distribution and execution of loaders across compromised networks.
Defensive Notes
  • Use licensed antivirus software with regularly updated signature databases.
  • Scan attachments from suspicious or untrusted senders. Treat unfamiliar counterparties, unusual sender domains, urgency, and references to government or regulatory bodies as warning signs.
  • Scan password-protected archives and embedded files before opening them.
  • Display file extensions and verify that actual extensions match file icons; avoid files with deceptive multiple extensions.
  • Provide regular employee training and exercises addressing safe email use and social engineering.
  • The article lists PT NAD and PT NGFW detection verdicts for HuLoader, sid: 10011864, and Mythic C2 Loki Agent, sid: 10013028.
  • The article warns that runtime replacement of domains in LNK commands can evade security tools lacking dynamic analysis in a virtual environment.

Indicators of compromise

TypeIndicatorContext
DOMAINarctelecom[.]ruMythic Likho phishing domain impersonating telecom operators.
DOMAINcloudmaill[.]ruMythic Likho phishing domain used as an email sender identity in a HuLoader delivery attempt.
DOMAINcloudrc[.]ruMythic Likho phishing domain impersonating cloud storage services.
DOMAINconsultantl[.]ruMythic Likho phishing domain impersonating legal services.
DOMAINdns-shop-client[.]ruMythic Likho phishing domain impersonating retail companies.
DOMAINelectropriborzavod[.]ruMythic Likho phishing domain using an industrial impersonation theme.
DOMAINgkrzn[.]ruMythic Likho phishing domain using an industrial impersonation theme.
DOMAINgosinfobot[.]ruMythic Likho phishing domain impersonating government services.
DOMAINgosuslugi-help[.]ruMythic Likho phishing domain impersonating government services.
DOMAINgosuslugi-moskva[.]ruMythic Likho phishing domain impersonating government services.
DOMAINilcloud[.]ruMythic Likho phishing domain used to deliver HuLoader; its subdomains also supported the group's infrastructure.
DOMAINinfo-cloud[.]ruMythic Likho phishing domain impersonating cloud storage services.
DOMAINnpo-iskra[.]ruMythic Likho phishing domain using an industrial impersonation theme.
DOMAINnsitelecom[.]ruMythic Likho phishing domain impersonating telecom operators.
DOMAINshopdns[.]ruMythic Likho phishing domain impersonating retail companies.
DOMAINtelecomz[.]ruMythic Likho phishing domain impersonating telecom operators.
DOMAINvesti-news[.]ruMythic Likho phishing domain using a mass-media impersonation theme.
DOMAINwinrar64[.]ruMythic Likho phishing domain using a software impersonation theme.
DOMAINyuristconsultant[.]ruMythic Likho phishing domain impersonating legal services.
EMAILonimaruslade@gmail[.]comEmail in the trial license of the XenArmor Password Recovery copy used during intrusions. Researchers found no evidence linking its owner to the cybercriminal underground and considered possible prior compromise or unwitting involvement.
IPV445[.]144[.]67[.]86Russian server hosting ilcloud[.]ru subdomains in late January 2026; researchers associated its configuration with active C2 infrastructure.
IPV45[.]255[.]116[.]34Remote SMB server in an observed command mounting a share used to distribute malicious loaders.
IPV487[.]251[.]66[.]8Server used by Megatsune operators for Chisel tunneling and subsequently by Mythic Likho to host an SMB share containing loaders.

MITRE ATT&CK

T1003 · OS Credential DumpingMythic Likho runs Mimikatz to extract operating-system credentials, including privileged accounts.T1005 · Data from Local SystemOperators collect files and create local copies of databases found on compromised systems.T1016 · System Network Configuration Discoveryarp, ipconfig, and loader check-ins collect network configuration and adapter addresses.T1018 · Remote System DiscoveryOperators use net view and ping to discover or check other hosts in the compromised network.T1021.002 · SMB/Windows Admin SharesPsExec and mounted SMB shares support remote execution and distribution of HuLoader, Merlin, and ReflectPulse.T1021.003 · Distributed Component Object ModelThe group uses DcomExec from Impacket to execute remote commands during lateral movement.T1021.004 · SSHOperators use SSH access and keys previously established in compromised networks, including access attributed to (Ex)Cobalt.T1027 · Obfuscated Files or InformationLoader commands disguise malicious domains through runtime substitution; payload resources and configurations also use encryption and obfuscation.T1027.007 · Dynamic API ResolutionDroppers dynamically resolve function addresses using a modified DJB2 hash algorithm.T1033 · System Owner/User DiscoveryThe group runs whoami, and loader check-ins include the current user name.T1036.005 · Match Legitimate Resource Name or LocationPersistence payloads are named NVIDIAControlPanel.exe, yandexupdate.exe, Telegram.exe, or chrome.exe to resemble legitimate software.T1036.007 · Double File ExtensionMalicious files use double extensions to resemble PDF documents and other benign decoys.T1036.008 · Masquerade File TypeSCR and LNK payloads use PDF and JPG icons to appear to be harmless documents or images.T1039 · Data from Network Shared DriveThe group collects data from network shares and databases across the compromised network.T1041 · Exfiltration Over C2 ChannelLoki uploads stolen files to C2 servers.T1046 · Network Service DiscoveryMythic Likho runs Nmap on compromised hosts for network reconnaissance.T1049 · System Network Connections DiscoveryThe group runs netstat to retrieve network connection statistics.T1055 · Process InjectionLoki supports a command to load and execute code within a specified process.T1057 · Process DiscoveryGet-Process retrieves running processes, and loaders report their current process identifiers.T1059.001 · PowerShellPowerShell downloads and launches payloads, gathers host information, mounts shares, and archives collected files.T1059.003 · Windows Command ShellLNK loaders invoke command-shell commands with delayed variable expansion to construct payload download URLs.T1071.001 · Web ProtocolsLoaders and Loki communicate with C2 servers using HTTP GET and POST requests and configured endpoints.T1078.003 · Local AccountsStolen local credentials are used to execute commands on other hosts during lateral movement.T1082 · System Information DiscoveryOperators run systeminfo, Get-Volume, and Get-PSDrive, while loaders collect operating-system and host details.T1083 · File and Directory DiscoveryCommands including ls, dir, tree, and recursive Get-ChildItem enumerate files and directories.T1087.002 · Domain AccountGet-ADUser and SharpHound collect information about Active Directory users.T1105 · Ingress Tool TransferLoaders download Loki, and operators transfer additional tools to infected hosts through the backdoor or SFTP.T1135 · Network Share DiscoveryGet-SMBShare and net view identify available network shares and shared resources.T1136.001 · Local AccountNew local operating-system users are created on compromised hosts to maintain access.T1140 · Deobfuscate/Decode Files or InformationDroppers decrypt and decompress embedded resources, while loaders decrypt configurations and the Loki payload before execution.T1201 · Password Policy DiscoveryOperators query password policies using net accounts, Get-ADDefaultDomainPasswordPolicy, and Get-WssPasswordPolicy.T1204.002 · Malicious FileVictims open SCR or LNK files packaged with decoy documents, triggering subsequent loader execution.T1485 · Data DestructionOperators format RAID arrays during the destructive final stage.T1486 · Data Encrypted for ImpactMythic Likho deploys LockBit to encrypt data across the compromised network.T1489 · Service StopOperators use Loki to terminate system processes during the impact phase.T1490 · Inhibit System RecoveryThe group removes backup and recovery tools during the final stage of attacks.T1547.001 · Registry Run Keys / Startup FolderOperators add Loki startup entries under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.T1552.001 · Credentials In FilesXenArmor Password Recovery Pro is used to extract credentials from the file system.T1560.001 · Archive via UtilityPowerShell Compress-Archive packages collected data before exfiltration.T1562.001 · Disable or Modify ToolsMythic Likho disables antivirus software on compromised hosts.T1566.002 · Spearphishing LinkTargeted emails contain links to malicious packages; links may follow an initial trust-building exchange.T1567.002 · Exfiltration to Cloud StorageRclone transfers collected data to cloud storage.T1572 · Protocol TunnelingLigolo-ng, PuTTY, Socat, and Chisel establish tunnels into compromised networks.T1573.001 · Symmetric CryptographyLoader messages use AES encryption; ReflectPulse uses AES-CBC with HMAC-SHA-256 verification for C2 data.T1583.001 · DomainsThe group registers domains impersonating cloud storage services, organizations, and industry-specific counterparties.T1583.003 · Virtual Private ServerMythic Likho rents virtual servers for malicious tools and C2 infrastructure.T1583.006 · Web ServicesOperators create cloud storage accounts to host payloads and register email accounts for phishing correspondence.T1584.004 · ServerThe group compromises Russian organizational websites and uses them to host malicious payloads.T1586.002 · Email AccountsCompromised organizational email accounts are used for phishing and direct communication with victims.T1589.002 · Email AddressesMythic Likho researches employee email addresses to prepare targeted phishing.T1591 · Gather Victim Org InformationOperators research target industries, locations, business partners, and employee roles to tailor attacks and cover stories.T1620 · Reflective Code LoadingDropper 2 reflectively loads loader DLLs, and the loader reflectively loads Loki from process memory.

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles