Calisto shows interest in entities involved in Ukraine war support
ID: 00a21aef-7ccd-54c2-abcc-f76012ca489d
STIX ID: report--00a21aef-7ccd-54c2-abcc-f76012ca489d
Feed Name: Sekoia.com
This Sekoia report attributes a long-running, suspected Russian-linked intrusion set called Calisto to targeted credential-phishing campaigns against Western and Eastern European entities (notably US and Ukrainian defense/logistics companies, NGOs, and think tanks). Analysts describe the use of weaponized PDFs that prompt victims to visit EvilGinx-based phishing pages, document a 80+ domain infrastructure including typosquats of Russian services, present victimology linking activity to Ukraine-related support organizations, and publish IOCs to enable detection and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
