logo

French NGO Reporters Without Borders targeted by Calisto in recent campaign

ID: d1422c20-d8ad-5288-ac5d-8913f87100b3

STIX ID: report--d1422c20-d8ad-5288-ac5d-8913f87100b3

Feed Name: Sekoia.io Blog

Threat Score
88/100

Date Published: 2025-12-03

Date Updated: 2026-04-29

Author: Sekoia TDR

...
...

Executive summary: This Sekoia TDR report documents active Calisto (ColdRiver) spear-phishing campaigns in 2025 targeting NGOs (including Reporters Without Borders), think tanks and Ukraine-supporting entities. The actor uses ProtonMail impersonation, ‘missing attachment’ or encrypted-PDF decoys redirected via compromised websites to an adversary-in-the-middle ProtonMail phishing kit that can capture credentials and 2FA; the report includes phishing-kit analysis, infrastructure details and a long list of redirector URLs and domains observed as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.