Callisto Group | F-Secure Labs Malware Analysis
ID: 169fcfa0-47f8-4d23-b856-1e6249b81c41
STIX ID: report--169fcfa0-47f8-4d23-b856-1e6249b81c41
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2017-04-13
Last Modified Date: 2017-04-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
F‑Secure describes the Callisto Group, an advanced espionage-focused threat actor active since late 2015 that used targeted credential phishing to harvest webmail credentials and follow-up spear‑phishing with malicious .docx attachments embedding the 'Scout' backdoor from the HackingTeam RCS Galileo platform. Targets included military personnel, government officials, think‑tank staff, and journalists in Europe and the South Caucasus; the report provides TTPs, mitigation/remediation guidance, and IoCs (sample hash, C2 IP, numerous phishing domains).
