Threat Actor ๐ท๐บ Russia
Callisto
Also known as: COLDRIVER ยท SEABORGIUM ยท TA446 ยท GOSSAMER BEAR ยท BlueCharlie ยท Star Blizzard ยท TAG-53 ยท IRON FRONTIER ยท UNC4057 ยท Blue Callisto
The Callisto Group is an advanced threat actor whose known targets include military personnel, government officials, think tanks, and journalists in Europe and the South Caucasus. Their primary interest appears to be gathering intelligence related to foreign and security policy in the Eastern Europe and South Caucasus regions.
Indicators of Compromise 22
Domain applicationformsubmit[.]me Domain blintepeeste[.]org Domain captchanom[.]top Domain documentsec[.]com Domain documentsec[.]online Domain inspectguarantee[.]org Domain ned-granting-opportunities[.]com Domain onstorageline[.]com Domain oxwoocat[.]org Domain preentootmist[.]org Domain southprovesolutions[.]com Domain system-healthadv[.]com Domain viewerdoconline[.]com SHA-256 2e74f6bd9bf73131d3213399ed2f669ec5f75392de69edf8ce8196cd70eb6aee SHA-256 3b49904b68aedb6031318438ad2ff7be4bf9fd865339330495b177d5c4be69d1 SHA-256 87138f63974a8ccbbf5840c31165f1a4bf92a954bacccfbf1e7e5525d750aa48 SHA-256 b60100729de2f468caf686638ad513fe28ce61590d2b0d8db85af9edc5da98f9 SHA-256 bce2a7165ceead4e3601e311c72743e0059ec2cd734ce7acf5cc9f7d8795ba0f SHA-256 c4d0fba5aaafa40aef6836ed1414ae3eadc390e1969fdcb3b73c60fe7fb37897 SHA-256 e9c8f6a7dba6e84a7226af89e988ae5e4364e2ff2973c72e14277c0f1462109b SHA-256 f2da013157c09aec9ceba1d4ac1472ed049833bc878a23bc82fe7eacbad399f4 IP 85[.]239[.]52[.]32
MITRE ATT&CK TTPs 12
T1012 T1027 T1053.005 T1055 T1059.001 T1059.003 T1071.001 T1082 T1087.002 T1105 T1140 T1204.002
Query Registry
Discovery
Obfuscated Files or Information
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
System Information Discovery
Discovery
Domain Account
Discovery
Ingress Tool Transfer
Command And Control
Deobfuscate/Decode Files or Information
Defense Evasion
Malicious File
Execution