SYMBOLCOMMON_NAMEaka. SYNONYMS

Callisto  (Back to overview)

aka: Blue Callisto, BlueCharlie, COLDRIVER, GOSSAMER BEAR, IRON FRONTIER, SEABORGIUM, Star Blizzard, TA446, TAG-53, UNC4057

The Callisto Group is an advanced threat actor whose known targets include military personnel, government officials, think tanks, and journalists in Europe and the South Caucasus. Their primary interest appears to be gathering intelligence related to foreign and security policy in the Eastern Europe and South Caucasus regions.


Associated Families

There are currently no families associated with this actor.


References
2024-10-03MicrosoftSteven Masada
Protecting Democratic Institutions from Cyber Threats
Callisto
2024-10-03US Department of JusticeOffice of Public Affairs
Justice Department Disrupts Russian Intelligence Spear-Phishing Efforts
Callisto
2024-10-03US Court for the District of ColumbiaUS Court for the District of Columbia
Civil Action No. 1:24-cv-02719-RC: Microsoft vs. Star Blizzard
Callisto
2024-10-03CitizenLabAlyson Bruce
Disrupting COLDRIVER: U.S. court orders seizure of domains used in Russian cyberattacks
Callisto
2024-09-19PWCJohn Southworth
COLDWASTREL of space
Callisto
2024-08-14CitizenLabJohn Scott-Railton, Ksenia Ermoshina, Rebekah Brown, Ron Deibert
Rivers of Phish: Sophisticated Phishing Targets Russia’s Perceived Enemies Around the Globe
Callisto
2024-06-26edeca.netDavid Cannings
An interesting Callisto YARA rule
Callisto
2024-06-05MandiantJamie Collier, Michelle Cantos
Phishing for Gold: Cyber Threats Facing the 2024 Paris Olympics
Callisto
2024-04-25MandiantJamie Collier, Kelli Vanderlee
Poll Vaulting: Cyber Threats to Global Elections
Callisto
2024-01-18GoogleWesley Shields
Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware
RCS SPICA Callisto
2023-12-13SekoiaSekoia TDR
CALISTO doxxing: Sekoia.io findings concurs to Reuters’ investigation on FSB-related Andrey Korinets
Callisto
2023-12-07GOV.UKGov.UK
UK exposes attempted Russian cyber interference in politics and democratic processes
Callisto
2023-12-07Department of JusticeOffice of Public Affairs
Two Russian Nationals Working with Russia’s Federal Security Service Charged with Global Computer Intrusion Campaign
Callisto
2023-12-07MicrosoftMicrosoft Threat Intelligence
Star Blizzard increases sophistication and evasion in ongoing attacks
Callisto
2023-12-06NCSC UKNCSC UK
Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns: Updated and new research, updated vulnerabilities, security updates and revised actors.
Callisto
2023-12-05US District Court Northern District of California San FranciscoIsmail J. Ramsey
CR23-00447CRB: United States of America vs RUSLAN ALEKSANDROVICH PERETYATKO and ANDREY STANISLAVOVICH KORINETS
Callisto
2023-08-03DARKReadingNate Nelson
Russian APT 'BlueCharlie' Swaps Infrastructure to Evade Detection
Callisto
2023-08-02Recorded FutureInsikt Group
BlueCharlie, Previously Tracked as TAG-53, Continues to Deploy New Infrastructure in 2023
Callisto
2023-02-21SekoiaLivia Tibirna, Maxime A, Sekoia TDR
One Year After: The Cyber Implications of the Russo-Ukrainian War
Callisto
2023-02-15GoogleGoogle Threat Analysis Group, Mandiant
Fog of War: How the Ukraine Conflict Transformed the Cyber Threat Landscape
CaddyWiper Dharma HermeticWiper INDUSTROYER2 PartyTicket WhisperGate Callisto Curious Gorge MUSTANG PANDA Turla
2022-12-05PWCPWC
Blue Callisto orbits around US Laboratories in 2022
Callisto
2022-12-05Recorded FutureInsikt Group
Exposing TAG-53’s Credential Harvesting Infrastructure Used for Russia-Aligned Espionage Operations
Callisto
2022-12-05SekoiaFélix Aime, Maxime A, Sekoia TDR
Calisto show interests into entities involved in Ukraine war support
Callisto
2022-08-15MicrosoftDigital Threat Analysis Center (DTAC), Microsoft Threat Intelligence Center (MSTIC), Office 365 Threat Research Team
Disrupting SEABORGIUM’s ongoing phishing operations
Callisto
2022-07-22SekoiaThreat & Detection Research Team
CALISTO continues its credential harvesting campaign
Callisto
2022-07-19GoogleBilly Leonard
Continued cyber activity in Eastern Europe observed by TAG
CyberAzov APT28 Callisto Ghostwriter Sandworm Turla
2022-05-03GoogleBilly Leonard
Update on cyber activity in Eastern Europe
Callisto
2022-03-30GoogleBilly Leonard
Tracking cyber activity in Eastern Europe
Callisto Curious Gorge
2017-04-13F-SecureF-Secure Labs
Callisto Group
Callisto
2017-04-01F-SecureF-Secure Labs
CALLISTO GROUP
RCS Callisto

Credits: MISP Project