logo

Callisto Group | F-Secure Labs Malware Analysis

ID: 169fcfa0-47f8-4d23-b856-1e6249b81c41

STIX ID: report--169fcfa0-47f8-4d23-b856-1e6249b81c41

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2017-04-13

Last Modified Date: 2017-04-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
F‑Secure describes the Callisto Group, an advanced espionage-focused threat actor active since late 2015 that used targeted credential phishing to harvest webmail credentials and follow-up spear‑phishing with malicious .docx attachments embedding the 'Scout' backdoor from the HackingTeam RCS Galileo platform. Targets included military personnel, government officials, think‑tank staff, and journalists in Europe and the South Caucasus; the report provides TTPs, mitigation/remediation guidance, and IoCs (sample hash, C2 IP, numerous phishing domains).