logo

Callisto APT: Russia’s Persistent Espionage Operator

ID: 5ca47647-6a4f-5cd3-be35-5edb6800a20e

STIX ID: report--5ca47647-6a4f-5cd3-be35-5edb6800a20e

Feed Name: Brandefense Blog

Threat Score
90/100

Date Published: 2025-12-23

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

**Executive summary:** This report profiles the Russia-linked Callisto APT, an espionage-focused threat actor active since at least 2015 that targets governments, defense institutions, think tanks, NGOs, and academia—particularly NATO- and EU-aligned organizations. It documents Callisto's evolution toward cloud-focused operations (OAuth consent phishing, token theft), persistent credential harvesting, rapid infrastructure rotation, use of web shells and lightweight backdoors, and targeted exfiltration of high-value diplomatic and policy information, and provides mitigations such as phishing-resistant MFA, OAuth monitoring, web shell hunting, and least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.