Uptime Hamster: 10d 9h 34mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Mythic Likho

Mythic Likho

0 incidentes 0 paises 0 sectores apt UA Ultimo: -
Aliases: Arcane Werewolf
Ver en IntelTracker → APTTrail →
Mythic Likho, also known as Arcane Werewolf, first emerged in campaigns observed in December 2024, utilizing custom Merlin and Loki malware. The group evolved its toolkit, notably deploying Loki 2.0 and later Loki 2.1 implants by late 2025. The group is assessed with moderate confidence to be of Ukrainian origin, given the naming "Likho" from Ukrainian folklore and its consistent targeting of Russian entities, particularly following the start of the Russo-Ukrainian conflict. Its primary motivation is cyberespionage, focusing on the exfiltration of sensitive information from targeted organizations. Mythic Likho distinguishes itself through the development and continuous refinement of its custom malware toolkit, specifically the Loki implant, which is compatible with the Mythic and Havoc post-exploitation frameworks. The group also utilizes highly deceptive techniques such as registering domain names that closely mimic those of their victim organizations to enhance the credibility of the

Aliases del actor

Arcane Werewolf

Actores similares

rare-werewolfactor · 1mythic-leopardactor · 1Angry Likhoapt · 0Awaken Likhoapt · 0ArcaneDoorapt · 0
Tipo
apt
Pais origen
UA
Motivacion
-
Impacto
1
Actualizado
Fri, 10 Ap