Callisto
COLDRIVERSEABORGIUMTA446GOSSAMER BEARBlueCharlieStar BlizzardTAG-53IRON FRONTIERUNC4057Blue CallistoCOLD RELICCallisto Group
The Callisto Group is an advanced threat actor whose known targets include military personnel, government officials, think tanks, and journalists in Europe and the South Caucasus. Their primary interest appears to be gathering intelligence related to foreign and security policy in the Eastern Europe and South Caucasus regions. Source: MISP
Attributed country: RU according to MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 29 Sep 2026 · last seen on 29 Sep 2026
News
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver BackdoorThe Hacker News · 29 Sep 2026
MITRE ATT&CK techniques
Reconnaissance
T1589Gather Victim Identity Information 3 Sigma rulesT1593Search Open Websites/Domains 2 Sigma rulesT1598.002Spearphishing AttachmentT1598.003Spearphishing Link
Resource Development
T1583Acquire InfrastructureT1583.001DomainsT1585.001Social Media AccountsT1585.002Email AccountsT1586.002Email AccountsT1588.002Tool 7 Sigma rulesT1608.001Upload Malware
Initial Access
Execution
Credential Access
Lateral Movement
Collection
Stealth
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗