SYMBOLCOMMON_NAMEaka. SYNONYMS

Callisto  (Back to overview)

aka: Blue Callisto, BlueCharlie, COLD RELIC, COLDRIVER, Callisto Group, GOSSAMER BEAR, IRON FRONTIER, Reuse Team, SEABORGIUM, Star Blizzard, TA446, TAG-53, UNC4057

The Callisto Group is an advanced threat actor whose known targets include military personnel, government officials, think tanks, and journalists in Europe and the South Caucasus. Their primary interest appears to be gathering intelligence related to foreign and security policy in the Eastern Europe and South Caucasus regions.


Associated Families
vbs.lostkeys win.yesrobot win.mayberobot win.norobot

References
2026-07-24 ⋅ Google ⋅ Google Threat Intelligence Group
Updated Cyber Threat Actor Naming System
APT15 APT20 APT27 APT28 APT29 APT30 APT31 APT33 APT35 APT37 APT39 APT40 APT41 APT42 APT45 APT5 BlackTech Callisto Conference Crew FIN11 FIN6 FIN7 FIN8 MuddyWater MUSTANG PANDA Naikon OilRig Sandworm TEMP.Hermit Tick Tonto Team Turla UAC-0020 UNC1069 UNC1088 UNC2814
2025-10-20 ⋅ Google ⋅ Wesley Shields
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER
MAYBEROBOT NOROBOT YESROBOT
2025-09-24 ⋅ Zscaler ⋅ Sudeep Singh, Yin Hong Chang
COLDRIVER Updates Arsenal with BAITSWITCH and SIMPLEFIX
NOROBOT
2025-05-07 ⋅ Google ⋅ Wesley Shields
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs
LOSTKEYS
2024-10-03 ⋅ US Court for the District of Columbia ⋅ US Court for the District of Columbia
Civil Action No. 1:24-cv-02719-RC: Microsoft vs. Star Blizzard
Callisto
2024-10-03 ⋅ Microsoft ⋅ Steven Masada
Protecting Democratic Institutions from Cyber Threats
Callisto
2024-10-03 ⋅ US Department of Justice ⋅ Office of Public Affairs
Justice Department Disrupts Russian Intelligence Spear-Phishing Efforts
Callisto
2024-10-03 ⋅ CitizenLab ⋅ Alyson Bruce
Disrupting COLDRIVER: U.S. court orders seizure of domains used in Russian cyberattacks
Callisto
2024-09-19 ⋅ PWC ⋅ John Southworth
COLDWASTREL of space
Callisto
2024-08-14 ⋅ CitizenLab ⋅ John Scott-Railton, Ksenia Ermoshina, Rebekah Brown, Ron Deibert
Rivers of Phish: Sophisticated Phishing Targets Russia’s Perceived Enemies Around the Globe
Callisto
2024-06-26 ⋅ edeca.net ⋅ David Cannings
An interesting Callisto YARA rule
Callisto
2024-06-05 ⋅ Mandiant ⋅ Jamie Collier, Michelle Cantos
Phishing for Gold: Cyber Threats Facing the 2024 Paris Olympics
Callisto
2024-04-25 ⋅ Mandiant ⋅ Jamie Collier, Kelli Vanderlee
Poll Vaulting: Cyber Threats to Global Elections
Callisto
2024-01-18 ⋅ Google ⋅ Wesley Shields
Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware
RCS SPICA Callisto
2023-12-13 ⋅ Sekoia ⋅ Sekoia TDR
CALISTO doxxing: Sekoia.io findings concurs to Reuters’ investigation on FSB-related Andrey Korinets
Callisto
2023-12-07 ⋅ GOV.UK ⋅ Gov.UK
UK exposes attempted Russian cyber interference in politics and democratic processes
Callisto
2023-12-07 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Star Blizzard increases sophistication and evasion in ongoing attacks
Callisto
2023-12-07 ⋅ Department of Justice ⋅ Office of Public Affairs
Two Russian Nationals Working with Russia’s Federal Security Service Charged with Global Computer Intrusion Campaign
Callisto
2023-12-06 ⋅ NCSC UK ⋅ NCSC UK
Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns: Updated and new research, updated vulnerabilities, security updates and revised actors.
Callisto
2023-12-05 ⋅ US District Court Northern District of California San Francisco ⋅ Ismail J. Ramsey
CR23-00447CRB: United States of America vs RUSLAN ALEKSANDROVICH PERETYATKO and ANDREY STANISLAVOVICH KORINETS
Callisto
2023-08-03 ⋅ DARKReading ⋅ Nate Nelson
Russian APT 'BlueCharlie' Swaps Infrastructure to Evade Detection
Callisto
2023-08-02 ⋅ Recorded Future ⋅ Insikt Group
BlueCharlie, Previously Tracked as TAG-53, Continues to Deploy New Infrastructure in 2023
Callisto
2023-02-21 ⋅ Sekoia ⋅ Livia Tibirna, Maxime A, Sekoia TDR
One Year After: The Cyber Implications of the Russo-Ukrainian War
Callisto
2023-02-15 ⋅ Google ⋅ Google Threat Analysis Group, Mandiant
Fog of War: How the Ukraine Conflict Transformed the Cyber Threat Landscape
CaddyWiper Dharma HermeticWiper INDUSTROYER2 PartyTicket WhisperGate Callisto Curious Gorge MUSTANG PANDA Turla
2022-12-05 ⋅ Recorded Future ⋅ Insikt Group
Exposing TAG-53’s Credential Harvesting Infrastructure Used for Russia-Aligned Espionage Operations
Callisto
2022-12-05 ⋅ PWC ⋅ PWC
Blue Callisto orbits around US Laboratories in 2022
Callisto
2022-12-05 ⋅ Sekoia ⋅ Félix Aime, Maxime A, Sekoia TDR
Calisto show interests into entities involved in Ukraine war support
Callisto
2022-08-15 ⋅ Microsoft ⋅ Digital Threat Analysis Center (DTAC), Microsoft Threat Intelligence Center (MSTIC), Office 365 Threat Research Team
Disrupting SEABORGIUM’s ongoing phishing operations
Callisto
2022-07-22 ⋅ Sekoia ⋅ Threat & Detection Research Team
CALISTO continues its credential harvesting campaign
Callisto
2022-07-19 ⋅ Google ⋅ Billy Leonard
Continued cyber activity in Eastern Europe observed by TAG
CyberAzov APT28 Callisto Ghostwriter Sandworm Turla
2022-05-03 ⋅ Google ⋅ Billy Leonard
Update on cyber activity in Eastern Europe
Callisto
2022-03-30 ⋅ Google ⋅ Billy Leonard
Tracking cyber activity in Eastern Europe
Callisto Curious Gorge
2017-04-13 ⋅ F-Secure ⋅ F-Secure Labs
Callisto Group
Callisto
2017-04-01 ⋅ F-Secure ⋅ F-Secure Labs
CALLISTO GROUP
RCS Callisto

Credits: MISP Project