Mythic Likho
0 incidentes
0 paises
0 sectores
apt UA Ultimo: -
Aliases: Arcane Werewolf
Mythic Likho, also known as Arcane Werewolf, first emerged in campaigns observed in December 2024, utilizing custom Merlin and Loki malware. The group evolved its toolkit, notably deploying Loki 2.0 and later Loki 2.1 implants by late 2025. The group is assessed with moderate confidence to be of Ukrainian origin, given the naming "Likho" from Ukrainian folklore and its consistent targeting of Russian entities, particularly following the start of the Russo-Ukrainian conflict. Its primary motivation is cyberespionage, focusing on the exfiltration of sensitive information from targeted organizations. Mythic Likho distinguishes itself through the development and continuous refinement of its custom malware toolkit, specifically the Loki implant, which is compatible with the Mythic and Havoc post-exploitation frameworks. The group also utilizes highly deceptive techniques such as registering domain names that closely mimic those of their victim organizations to enhance the credibility of the