logo

CALISTO continues its credential harvesting campaign

ID: 9f731a97-37ee-5cdb-ad1f-d3a38f26610a

STIX ID: report--9f731a97-37ee-5cdb-ad1f-d3a38f26610a

Feed Name: Sekoia.com

Threat Score
70/100

Date Published: 2022-06-22

Date Updated: 2026-07-20

...
...

CALISTO (aka COLDRIVER) is running an active credential-harvesting spear-phishing campaign targeting Western NGOs, think tanks and defense organizations by using freshly created Gmail accounts and decoy documents hosted on legitimate services (Google Docs, OneDrive) to redirect victims to phishing domains. The actors leveraged Evilginx as an SSL reverse proxy to capture credentials and 2FA tokens; Sekoia identified approximately 24 Evilginx-related domains, documented multiple IOCs, and noted a PHP-based phishing page targeting the Ukrainian MOD among the infrastructure observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.