Bluecharlie

Threat Actor updated 7 months ago (2024-05-04T18:18:15.510Z)
Download STIX
Preview STIX
BlueCharlie, also known as TAG-53, Blue Callisto, Callisto (or Calisto), COLDRIVER, Star Blizzard (formerly SEABORGIUM), and TA446, is a threat actor that has been linked to Russia and has reportedly been active since 2019. The group has been involved in various malicious activities including cyberespionage, cyber influence campaigns, and phishing attacks, primarily targeting sectors such as international affairs, defense, and logistics support to Ukraine. It has been identified by the Computer Weekly as an operation of the Russian Federal Security Service (FSB). In August, Insikt Group, a division of Recorded Future, reported that BlueCharlie was linked to 94 new domains, indicating that the group has been actively modifying its infrastructure in response to public disclosures about its activities. This evolution in tactics showcases the group's adaptability and persistence. The new infrastructure is likely to be used for phishing campaigns and/or credential harvesting, pointing towards an increase in their cybercriminal activities. The group utilizes cloud-based platforms like HubSpot, MailerLite, and virtual private servers (VPS) partnered with server-side scripts to prevent automated scanning. According to Zoey Selman, a threat intelligence analyst at Recorded Future's Insikt Group, this approach enables BlueCharlie to set allow parameters to redirect victims to threat actor infrastructure only when certain requirements are met. Recently, researchers observed the group using email marketing services to target think tanks and research organizations with the aim of obtaining credentials for a U.S. grants management portal.
Description last updated: 2024-05-04T17:17:45.714Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
COLDRIVER is a possible alias for Bluecharlie. Coldriver, also known as Star Blizzard, Callisto, and Seaborgium, is a Russia-based cyber-espionage group believed to be backed by the Federal Security Service (FSB). This threat actor has been active since at least 2015, targeting government officials, military personnel, journalists, think tanks,
5
Seaborgium is a possible alias for Bluecharlie. Seaborgium, also known by various names such as Star Blizzard, Callisto Group, COLDRIVER, and TAG-53, is a threat actor believed to be linked to Russia's Federal Security Service (FSB). The group has been active since at least 2015, targeting government officials, military personnel, journalists, an
4
Calisto is a possible alias for Bluecharlie. Calisto, also known as BlueCharlie, Blue Callisto, TAG-53, COLDRIVER, Star Blizzard (formerly SEABORGIUM), TA446, and UNC4057, is a threat actor that has been active since 2019. This group targets a wide range of sectors and is particularly focused on individuals and organizations involved in intern
3
TA446 is a possible alias for Bluecharlie. TA446, also known as the Callisto APT group, Seaborgium, Star Blizzard, ColdRiver, TAG-53, and BlueCharlie, is a significant threat actor that has been active since at least 2015. The group has persistently targeted government officials, military personnel, journalists, and think tanks, focusing on
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Domains
Blizzard
Phishing
Espionage
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The threatActor Starblizzard is associated with Bluecharlie. Unspecified
2
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The vulnerability Blizzard/seaborgium is associated with Bluecharlie. Unspecified
2
The vulnerability Star Blizzard/seaborgium is associated with Bluecharlie. Unspecified
2
Source Document References
Information about the Bluecharlie Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
10 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
DARKReading
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Securelist
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
DARKReading
a year ago
Recorded Future
a year ago
CERT-EU
a year ago
CERT-EU
a year ago