COLDRIVER, also known as Calisto, Callisto, and Star Blizzard, is a Russian-nexus cyber-espionage intrusion set active since at least 2017. The group is widely associated with long-running spearphishing and credential-harvesting operations directed at organizations and individuals of strategic interest to Russia. Reported victimology includes Western NGOs, think tanks, defense-related entities, logistics and military-support companies, communications providers, cybersecurity firms, journalists, former intelligence officials, experts on Russian affairs, and organizations involved in Ukraine support, conflict resolution, war-crime documentation, and international justice processes. The activity has also included targeting of Reporters Without Borders and entities linked to NATO and the broader defense ecosystem. The actor’s tradecraft centers on socially engineered phishing campaigns designed to steal credentials and, in some cases, session material. COLDRIVER has used impersonation of trusted contacts, rapport-building exchanges, spoofing, decoy documents, malicious PDF lures, and “missing attachment” themes to induce victims to open follow-up content. The group has repeatedly leveraged legitimate cloud and email services as part of delivery and redirection chains to reduce suspicion and evade gateway inspection. Multiple investigations have linked the actor to adversary-in-the-middle credential phishing using Evilginx-style infrastructure capable of harvesting credentials and bypassing some multifactor authentication workflows by capturing session tokens. Custom AiTM phishing has also been reported in later campaigns. Operationally, COLDRIVER appears focused on intelligence collection rather than disruption or monetization. Its targeting of logistics, military equipment, and communications organizations supporting Ukraine is consistent with efforts to map or monitor supply chains relevant to Kyiv’s defense. Targeting of NGOs and justice-focused organizations is consistent with collection on war-crime evidence, diplomatic activity, and policy deliberations. Public reporting has described the group as Russia-nexus and, in some reporting, FSB-associated, but direct attribution to a specific Russian service is not uniformly established across all reporting. Claims linking COLDRIVER to Gamaredon have not been broadly supported by technical overlap analyses.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
108 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spear-phishing campaigns targeting NGOs, using impersonation and benign attachments to increase credibility.
Spear-phishing/credential-harvesting operations using rapport-building and multi-step lures (missing-attachment follow-up), redirectors, and cloud-hosted payload delivery (e.g., ProtonDrive) to gain initial access.
Targeting Reporters Without Borders using custom adversary-in-the-middle phishing and a "missing file" lure.
Russia-nexus (FSB-associated per the report) intrusion set conducting phishing/credential theft against logistics companies supporting Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.