CALISTO continues its credential harvesting campaign
ID: 9f731a97-37ee-5cdb-ad1f-d3a38f26610a
STIX ID: report--9f731a97-37ee-5cdb-ad1f-d3a38f26610a
Feed Name: Sekoia.com
CALISTO (aka COLDRIVER) is running an active credential-harvesting spear-phishing campaign targeting Western NGOs, think tanks and defense organizations by using freshly created Gmail accounts and decoy documents hosted on legitimate services (Google Docs, OneDrive) to redirect victims to phishing domains. The actors leveraged Evilginx as an SSL reverse proxy to capture credentials and 2FA tokens; Sekoia identified approximately 24 Evilginx-related domains, documented multiple IOCs, and noted a PHP-based phishing page targeting the Ukrainian MOD among the infrastructure observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
