Blue Charlie

Threat Actor updated 3 months ago (2024-05-24T02:17:31.805Z)
Download STIX
Preview STIX
Blue Charlie, also known as TAG-53, UNC4057, Star Blizzard, and Callisto, is a threat actor linked to Russian threat activity groups such as the Callisto Group, COLDRIVER, and SEABORGIUM. Both Microsoft and the UK government have assessed this connection. The entity is believed to be part of the wider landscape of state-sponsored cyber threats, executing malicious actions with the intent to compromise security, gather sensitive information, and disrupt operations. In December 2022, Recorded Future, a cybersecurity firm, profiled the phishing and credential harvesting infrastructure used by Blue Charlie for Russia-aligned espionage operations. The group has targeted a variety of entities including non-governmental organizations, think tanks, journalists, and government and defense officials. Their methods involve sophisticated phishing techniques aimed at compromising email accounts to gain unauthorized access to sensitive data. The threat actor has been found using a custom backdoor named "SPICA" on victim systems to steal information, execute arbitrary commands, and establish persistence. This indicates an advanced level of capability and suggests that the group is not just phishing for credentials but also delivering malware via campaigns. Recently, the group has evolved its tactics, techniques, and procedures (TTPs), moving beyond mere credential phishing to include malware delivery through PDF lure documents. These developments underscore the growing sophistication and persistent threat posed by Blue Charlie.
Description last updated: 2024-05-24T02:15:54.673Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Phishing
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Blue Charlie Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Krebs on Security
3 months ago
Stark Industries Solutions: An Iron Hammer in the Cloud
CERT-EU
8 months ago
Russian hacker Coldriver extends tactics to include custom malware | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting