logo

BlueCharlie, Previously Tracked as TAG-53, Continues to Deploy New Infrastructure in 2023

ID: 92b7737e-5059-5565-b1c7-bd4da8744858

STIX ID: report--92b7737e-5059-5565-b1c7-bd4da8744858

Feed Name: Recorded Future Blog

Threat Score
85/100

Date Published: 2023-08-02

Date Updated: 2026-07-20

...
...

Insikt Group reports that BlueCharlie, a Russia-linked espionage-focused threat actor active since 2017, has developed 94 new domains and altered TTPs consistent with phishing and credential-harvesting campaigns targeting government, defense, education, political organizations, NGOs, journalists, and think tanks; the analysis highlights the actor’s operational evolution and recommends stronger phishing defenses, FIDO2 MFA, threat intelligence usage, and vendor security education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.