BlueCharlie, Previously Tracked as TAG-53, Continues to Deploy New Infrastructure in 2023
ID: e305447e-81ca-460c-94dd-a51634371575
STIX ID: report--e305447e-81ca-460c-94dd-a51634371575
Threat Score
83/100
Uploaded: 2026-08-11
Published Date: 2023-08-02
Last Modified Date: 2023-08-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group attributes new infrastructure and active credential-harvesting phishing campaigns to BlueCharlie (previously TAG-53), a Russia-linked APT. Since March 2023 the group has spun up 94 domains and many IPs across specific registrars and ASNs, shifted domain-naming conventions and TTPs in response to public reporting, continues to rely on Let’s Encrypt certificates, and poses a persistent phishing threat to government, defense, higher education, NGOs, and related sectors; the report includes IOCs, ASN/registrar patterns, mitigations, and ATT&CK mappings.
