logo

Calisto shows interest in entities involved in Ukraine war support

ID: 00a21aef-7ccd-54c2-abcc-f76012ca489d

STIX ID: report--00a21aef-7ccd-54c2-abcc-f76012ca489d

Feed Name: Sekoia.com

Threat Score
82/100

Date Published: 2022-12-05

Date Updated: 2026-07-20

...
...

This Sekoia report attributes a long-running, suspected Russian-linked intrusion set called Calisto to targeted credential-phishing campaigns against Western and Eastern European entities (notably US and Ukrainian defense/logistics companies, NGOs, and think tanks). Analysts describe the use of weaponized PDFs that prompt victims to visit EvilGinx-based phishing pages, document a 80+ domain infrastructure including typosquats of Russian services, present victimology linking activity to Ukraine-related support organizations, and publish IOCs to enable detection and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.