Calisto

Threat Actor updated 7 months ago (2024-05-05T03:18:26.810Z)
Download STIX
Preview STIX
Calisto, also known as BlueCharlie, Blue Callisto, TAG-53, COLDRIVER, Star Blizzard (formerly SEABORGIUM), TA446, and UNC4057, is a threat actor that has been active since 2019. This group targets a wide range of sectors and is particularly focused on individuals and organizations involved in international affairs, defense, and logistics support to Ukraine. According to the Insikt Group, a Recorded Future threat research division, Calisto has been linked to 94 new domains since March this year, indicating an active modification of its infrastructure in response to public disclosures about its activities. Recorded Future has also identified this adversary as a contributor to Russian intelligence efforts, supporting Moscow's strategic interests. The cybersecurity firm noted that domain registration was one of the main skills used by this group, likely on behalf of Russian intelligence, either directly or through a contractor relationship. The group has been associated with cyberespionage, credential theft, and hack-and-leak operations aimed at Ukraine and NATO nations, amid increasing public disclosures regarding its activities. Despite these exposures, Calisto continues to evolve and establish new attack infrastructures. It has been observed that the group is persistently targeting entities related to Ukraine, disrupting Kiev's supply chain for military reinforcements. As such, continuous monitoring and mitigation strategies are crucial to counteract this persistent threat.
Description last updated: 2024-05-05T02:18:57.200Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Bluecharlie is a possible alias for Calisto. BlueCharlie, also known as TAG-53, Blue Callisto, Callisto (or Calisto), COLDRIVER, Star Blizzard (formerly SEABORGIUM), and TA446, is a threat actor that has been linked to Russia and has reportedly been active since 2019. The group has been involved in various malicious activities including cybere
3
COLDRIVER is a possible alias for Calisto. Coldriver, also known as Star Blizzard, Callisto, and Seaborgium, is a Russia-based cyber-espionage group believed to be backed by the Federal Security Service (FSB). This threat actor has been active since at least 2015, targeting government officials, military personnel, journalists, think tanks,
2
Seaborgium is a possible alias for Calisto. Seaborgium, also known by various names such as Star Blizzard, Callisto Group, COLDRIVER, and TAG-53, is a threat actor believed to be linked to Russia's Federal Security Service (FSB). The group has been active since at least 2015, targeting government officials, military personnel, journalists, an
2
TA446 is a possible alias for Calisto. TA446, also known as the Callisto APT group, Seaborgium, Star Blizzard, ColdRiver, TAG-53, and BlueCharlie, is a significant threat actor that has been active since at least 2015. The group has persistently targeted government officials, military personnel, journalists, and think tanks, focusing on
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Blizzard
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.