Who is Calisto (Star Blizzard / COLDRIVER)?
Calisto is a Russian state-sponsored cyber espionage group active since at least 2017, best known for patient, highly targeted spearphishing aimed at stealing credentials from people who matter to Russian intelligence. In December 2023, a joint statement by the United States, United Kingdom, Canada, Australia, and New Zealand attributed the group to Russia's Federal Security Service (FSB), specifically its Centre 18. The actor is tracked under several names, most commonly Calisto (also spelled Callisto), Star Blizzard, and COLDRIVER. Unlike groups that rely on elaborate malware, Calisto's tradecraft is built around social engineering and identity theft. It studies its targets, impersonates trusted contacts, and lures them to credential-harvesting pages, then uses the stolen access to collect intelligence or to leak material in support of Russian information operations. This page covers the group's attribution and aliases, who it targets, how it operates, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
Key takeaways
- Calisto is an FSB cyber espionage group. In December 2023 it was formally attributed to Russia's FSB Centre 18 by a coalition of Western governments.
- It goes by many names. Calisto, Star Blizzard, COLDRIVER, SEABORGIUM, TA446, and Blue Charlie all refer to the same actor.
- Spearphishing and credential theft are its core method. It impersonates trusted contacts and steals credentials, including multi-factor authentication tokens, rather than deploying complex malware.
- Its targets are politically significant. Government, defense, NGOs, think tanks, journalists, academics, and Kremlin critics, especially those connected to Ukraine, are the focus.
- It runs hack-and-leak operations. Stolen material has been selectively leaked and amplified to serve Russian information objectives.
Attribution and aliases
On 7 December 2023, the United States, United Kingdom, Canada, Australia, and New Zealand jointly attributed this actor to the Russian FSB's Centre 18, the Centre for Information Security. The United States and United Kingdom also imposed sanctions on two Russian nationals, Ruslan Peretyatko and Andrey Korinets, linked to the group's operations. Western intelligence assesses the group is almost certainly subordinate to FSB Centre 18, placing it firmly among Russia's state-directed cyber espionage efforts.
Because many vendors and governments have tracked the group independently, it carries a long list of names. The most common are below:
- Calisto / Callisto (also "Callisto Group")
- Star Blizzard (formerly SEABORGIUM)
- COLDRIVER
- TA446
- Blue Charlie
- Blue Callisto
- TAG-53
It is worth being precise about how attribution developed, because it shows how threat intelligence matures over time. When Sekoia first published on Calisto in 2022, its analysts deliberately declined to tie the group to Russian intelligence, noting only that the targeting aligned with Russian strategic interests. After the 2023 government attribution and Sekoia's own follow-up investigation, the picture became clear, and Sekoia now concurs that Calisto works in support of the FSB. That progression, from cautious observation to confident attribution backed by evidence, is how responsible intelligence work is meant to proceed.
Who Calisto targets
Calisto's targeting tracks Russian intelligence priorities closely, with a heavy focus on countries and individuals connected to Ukraine and to criticism of the Kremlin. Its usual targets include:
- Government and defense, including parliamentarians and defense contractors, particularly in the United Kingdom, United States, and Eastern Europe.
- NGOs and think tanks, such as the Institute for Statecraft, whose work touches on defending democracy and countering disinformation.
- Journalists and academics, including experts in Russian affairs and, in a 2025 campaign, the press-freedom NGO Reporters Without Borders.
- Kremlin critics and Russian citizens abroad, including former intelligence officials and dissidents.
The group's operations have repeatedly aligned with moments of political significance, and its hack-and-leak activity, such as the leak of UK-US trade documents ahead of the 2019 UK general election, points to a goal of shaping opinion as well as gathering intelligence.
How Calisto operates
Calisto's method is deliberate and low-tech relative to many state actors, which is part of what makes it effective. A typical operation follows a recognizable pattern:
- Research and impersonation. The group studies a target and creates convincing personas, often impersonating a known colleague, an expert, or an institution the target would trust, sometimes building rapport over several benign emails first.
- Lure delivery. It sends a message pointing to a document, frequently using a legitimate service such as Google Docs or Microsoft OneDrive to host a decoy. Because the email itself carries no malicious link, it slips past many mail-gateway checks.
- Credential harvesting. The link leads to a phishing page. Sekoia's TDR team documented Calisto using the open-source tool Evilginx as a reverse proxy, which sits between the target and the real login page to capture not only the password but also the multi-factor authentication token, defeating that protection.
- Access and exploitation. With valid credentials and session tokens, the group reads the target's mailbox and data, and in some cases exfiltrates material for later selective leaking.
Historically Calisto has favored this credential-theft approach over custom malware, though more recent reporting has noted the group beginning to use its own malware in some operations. Its infrastructure has been large and reasonably disciplined: Sekoia linked two dozen Evilginx domains to the group with medium-to-high confidence, though the operators occasionally made mistakes, such as leaving default redirects in place, that helped researchers map their servers.
Sekoia's research on Calisto
Sekoia's TDR team has tracked Calisto across several years of first-party investigation, which is part of why the group is well understood. In 2022, TDR analyzed the group's credential-harvesting infrastructure and its use of Evilginx. In a follow-up investigation, published after a Reuters report, Sekoia detailed technical links between the group's phishing infrastructure and Andrey Korinets, one of the Russian nationals later sanctioned, whose apparent role was registering phishing domains. In 2025, TDR analyzed a fresh spearphishing campaign after being contacted by targeted organizations, including Reporters Without Borders. This body of work, cited by international reporting, is the kind of first-hand intelligence that turns a name in an advisory into an actor a defender can actually recognize and counter.
How to defend against Calisto
Because Calisto attacks people and credentials rather than software, defense centers on identity and awareness:
- Deploy phishing-resistant MFA. Since the group steals multi-factor authentication tokens through reverse-proxy phishing, phishing-resistant methods such as FIDO2 security keys and passkeys, which bind authentication to the real site, are the single most effective countermeasure.
- Train high-risk individuals. People in government, defense, NGOs, journalism, and Russian-affairs research should be briefed on the group's impersonation tactics and its use of trusted cloud services to host lures.
- Scrutinize login pages and links. Encourage targets to verify the true destination of any link asking for credentials, and to be wary of unexpected document-sharing requests, even from apparently known contacts.
- Detect the post-compromise signals. Watch for anomalous sign-ins, impossible-travel logins, and unusual mailbox access that indicate stolen credentials are being used, and use threat intelligence to block known Calisto infrastructure.
Expert insight: a low-tech actor that beats high-tech defenses
Calisto is a useful reminder that a threat actor does not need advanced malware to be dangerous. Its entire operation turns on trust: a believable person, a familiar-looking document, a login page that looks right. There is no exploit for a scanner to catch and often no malicious attachment for a gateway to strip. When the group harvests a multi-factor authentication token through a reverse proxy, even that safeguard is bypassed, and the intrusion continues as a perfectly valid login.
This is where a CTI-led approach matters, and where Sekoia's work on Calisto is instructive. Sekoia is a European cybersecurity vendor whose TDR team tracks actors like this one directly, and that intelligence, known infrastructure, phishing patterns, and tradecraft, feeds its platform so the activity is recognized rather than missed. Because the damaging part of a Calisto operation is the use of stolen credentials, detection depends on correlating identity signals, such as an anomalous sign-in or session token used from an unfamiliar location, with the wider context, mapped to the MITRE ATT&CK framework. A single suspicious login means little on its own; read against current intelligence on the actor, it becomes a lead. As a European vendor with a data-sovereignty posture, Sekoia is well placed to support the government, defense, and civil-society organizations that actors like Calisto target.