blue_callisto
Blue Callisto, also known as SEABORGIUM and Callisto Group, is a likely Russia-based threat actor that has primarily conducted phishing attacks for espionage purposes since at least 2017. Reported targeting includes US and European government officials and organizations linked to national security matters, the UK Foreign Office in 2017, UK and US universities in 2020 and 2022, and entities connected to nuclear non-proliferation work. Since the start of the Russo-Ukraine war in 2022, the actor has shown increased interest in Ukraine, including at least one private Ukrainian logistics-related company, and in October 2022 was observed targeting an organization investigating war crimes. Observed tradecraft in 2022 included credential-harvesting phishing infrastructure using Google-themed sign-in pages, statically prefilled victim email addresses, browser-fingerprinting JavaScript to identify automated scanners and antivirus technologies before redirecting victims, and use of phishing technologies such as Evilginx. The reported activity was mapped to MITRE ATT&CK techniques T1566.002, T1059.007, T1140, and T1082. The actor remained active in 2022, making modest infrastructure and tooling changes while continuing to use phishing TTPs observed as far back as 2019.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Academia & Research
- Commercial & Professional Services
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇬🇧 United Kingdom
- 🇺🇦 Ukraine
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.