TA446

Threat Actor updated 4 months ago (2024-05-04T20:52:11.847Z)
Download STIX
Preview STIX
TA446, also known as the Callisto APT group, Seaborgium, Star Blizzard, ColdRiver, TAG-53, and BlueCharlie, is a threat actor that has been active since at least 2015. This cyberespionage entity has persistently targeted individuals and organizations involved in international affairs, defense, and logistics support to Ukraine. Their targets predominantly include government officials, military personnel, journalists, and think tanks. The group's activities have been tracked by both government and industry researchers, demonstrating its significant impact on cybersecurity. In August, Insikt Group, a Recorded Future threat research division, reported that TA446 was linked to 94 new domains starting from March this year. This suggests that the group is actively modifying its infrastructure in response to public disclosures about its activities. This continuous change in attack infrastructure signifies the group's adaptability and resilience against security measures and public exposure. The U.S. and UK governments have identified TA446 as being linked to Russia’s Federal Security Service (FSB), specifically its Center 18 cyberespionage unit. This association with a state-sponsored entity indicates a high level of sophistication and resources behind TA446's operations. In conclusion, TA446 represents a serious and evolving threat to global cybersecurity, particularly for entities involved in international affairs and defense.
Description last updated: 2024-05-04T17:18:26.458Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
COLDRIVER
3
Coldriver, also known as Star Blizzard, (Blue) Callisto, Blue Charlie, and Seaborgium, is a notorious Russia-based cyber-espionage group believed to be linked to the Federal Security Service's (FSB) Centre 18. The group has been actively involved in numerous malicious activities, including disinform
Seaborgium
3
Seaborgium, also known as Star Blizzard, Callisto Group, COLDRIVER, and TAG-53, is a threat actor linked to suspected Russian threat activity groups. Open-source reporting has enabled Insikt Group to profile the infrastructure used by this group, revealing significant overlaps with other known malic
Bluecharlie
2
BlueCharlie, also known as TAG-53, Blue Callisto, Callisto (or Calisto), COLDRIVER, Star Blizzard (formerly SEABORGIUM), and TA446, is a threat actor that has been linked to Russia and has reportedly been active since 2019. The group has been involved in various malicious activities including cybere
Calisto
2
Calisto, also known as BlueCharlie, Blue Callisto, TAG-53, COLDRIVER, Star Blizzard (formerly SEABORGIUM), TA446, and UNC4057, is a threat actor that has been active since 2019. This group targets a wide range of sectors and is particularly focused on individuals and organizations involved in intern
Callisto
2
Callisto, also known as Gossamer Bear, COLDRIVER, UNC4057, Star Blizzard, Blue Charlie, and SEABORGIUM, is a threat actor linked to the Russian state. This group, which has been tracked by various entities including Microsoft, Google's Threat Analysis Group (TAG), and Insikt Group, is known for its
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Blizzard
Apt
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the TA446 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
8 months ago
Google TAG warns that Russian COLDRIVER APT is using a custom backdoor
CERT-EU
9 months ago
Microsoft Alert: COLDRIVER Credential Theft Rising Again
CERT-EU
9 months ago
UK names Russian FSB agents behind political hacking campaign | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
9 months ago
US, UK accuse Russia’s Callisto Group of cyber espionage, political interference
CERT-EU
9 months ago
Russian FSB Targets US and UK Politicians in Sneaky Spear-Phish Plan
CERT-EU
9 months ago
US and British authorities sanction, indict Russian hackers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
9 months ago
UK and US expose Russia Callisto Group's activity and sanction members
CERT-EU
9 months ago
US and British authorities sanction, indict Russian hackers
CERT-EU
9 months ago
Microsoft Warns of COLDRIVER's Evolving Evading and Credential-Stealing Tactics
CERT-EU
a year ago
BlueCharlie changes attack infrastructure in response to reports on its activity
CERT-EU
10 months ago
Advanced threat predictions for 2024 – GIXtools
Securelist
10 months ago
Kaspersky Security Bulletin: APT predictions 2024
CERT-EU
a year ago
Russian Cyber Adversary BlueCharlie Alters Infrastructure in Response to Disclosures