Callisto

Threat Actor updated a month ago (2024-10-15T10:02:10.248Z)
Download STIX
Preview STIX
Callisto, also known as Star Blizzard, COLDRIVER, TAG-53, and BlueCharlie, is a threat actor group likely based in Russia that has been linked to malicious cyber activities. The group is notorious for its sophisticated spear-phishing attacks targeting organizations and individuals in the UK and other areas of interest for information-gathering purposes. Insikt Group, leveraging open-source reporting, identified new infrastructure used by TAG-53, which shows significant overlap with Callisto Group, COLDRIVER, and SEABORGIUM. This consistent setup pattern suggests a strong connection between these entities. In December 2023, the U.S. Department of Justice announced charges against two Callisto-affiliated actors, Ruslan Aleksandrovich Peretyatko, an officer in FSB Center 18, and Andrey Stanislavovich Korinets. The Callisto Group targeted various entities, including U.S.-based companies, former and current employees of the U.S. Intelligence Community, Department of Defense and Department of State, U.S. military defense contractors, and Department of Energy staff. In response, Microsoft filed a civil action to seize 66 internet domains used by the Callisto Group, tracked by Microsoft Threat Intelligence as 'Star Blizzard'. Despite these actions, the Callisto Group remains active and continues to pose a significant cybersecurity threat. The group primarily uses phishing emails to steal login credentials and has recently developed a custom backdoor. In October 2024, a coordinated effort by the U.S. Department of Justice and Microsoft's Digital Crimes Unit disrupted a spear-phishing campaign orchestrated by Star Blizzard, resulting in the seizure of 107 internet domains linked to the group. However, this action is unlikely to end the group's spear-phishing activity, indicating the persistent threat posed by Callisto and affiliated groups.
Description last updated: 2024-10-15T09:28:31.557Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Star Blizzard is a possible alias for Callisto. Star Blizzard, a threat actor group with ties to Russia's FSB, has been conducting sophisticated spear-phishing campaigns predominantly targeting Western think tanks, government officials, defense contractors, journalists, and nongovernmental organizations (NGOs). The group uses spear-phishing techn
6
COLDRIVER is a possible alias for Callisto. Coldriver, also known as Star Blizzard, Callisto, and Seaborgium, is a Russia-based cyber-espionage group believed to be backed by the Federal Security Service (FSB). This threat actor has been active since at least 2015, targeting government officials, military personnel, journalists, think tanks,
6
Seaborgium is a possible alias for Callisto. Seaborgium, also known by various names such as Star Blizzard, Callisto Group, COLDRIVER, and TAG-53, is a threat actor believed to be linked to Russia's Federal Security Service (FSB). The group has been active since at least 2015, targeting government officials, military personnel, journalists, an
6
Callisto Group is a possible alias for Callisto. The Callisto Group, also known as 'Star Blizzard', 'SEABORGIUM', and 'COLDRIVER', is a threat actor linked to Russia's Federal Security Service (FSB), Center 18. This group has been involved in sophisticated spear-phishing campaigns aimed at unauthorized access and information theft from protected c
4
TA446 is a possible alias for Callisto. TA446, also known as the Callisto APT group, Seaborgium, Star Blizzard, ColdRiver, TAG-53, and BlueCharlie, is a significant threat actor that has been active since at least 2015. The group has persistently targeted government officials, military personnel, journalists, and think tanks, focusing on
2
Cold River is a possible alias for Callisto. Cold River, also known as Star Blizzard, Callisto, and UNC4057, is a sophisticated threat actor linked to the Kremlin. The group has been associated with numerous cyber espionage activities that align with Russian interests. Chief analyst at cybersecurity specialist Mandiant, John Hultquist, has att
2
Unc4057 is a possible alias for Callisto. UNC4057, also known as ColdRiver, Star Blizzard, Blue Charlie, and Callisto, is a Russian-backed advanced persistent threat (APT) group that has been active since 2019. This group, sponsored by the Federal Security Service (FSB), has been involved in various malicious activities on behalf of the Rus
2
Gossamer Bear is a possible alias for Callisto. Gossamer Bear, also known as Callisto, Blue Callisto, BlueCharlie (or TAG-53), Calisto, Star Blizzard (formerly SEABORGIUM), TA446, and UNC4057, is a significant threat actor that has been active since 2019. The group primarily focuses on credential harvesting and conducts hack-and-leak campaigns ta
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Phishing
Blizzard
Apt
Ukraine
Russia
Fsb
Backdoor
Malware
Domains
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Callisto Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Flashpoint
a month ago
DARKReading
2 months ago
Flashpoint
2 months ago
BankInfoSecurity
2 months ago
CISA
a year ago
CERT-EU
10 months ago
BankInfoSecurity
5 months ago
Flashpoint
6 months ago
DARKReading
7 months ago
DARKReading
7 months ago
CERT-EU
9 months ago
ESET
2 years ago
InfoSecurity-magazine
9 months ago
CERT-EU
10 months ago
CERT-EU
10 months ago
CERT-EU
10 months ago
DARKReading
10 months ago
CERT-EU
10 months ago
CERT-EU
10 months ago
Securityaffairs
10 months ago