Calisto is a macOS backdoor associated with credential theft, host reconnaissance, local data collection, staging, and exfiltration. It has been distributed as an unsigned disk image masquerading as a legitimate macOS security product, indicating a social-engineering-driven initial infection vector. Once executed, it can prompt the user for their macOS login credentials, gather host network information by invoking native system utilities to obtain the victim’s IP address, and collect data from user directories and Google Chrome bookmarks. Calisto stages stolen information in a hidden directory before compressing it with native archiving commands for exfiltration. It also establishes persistence on macOS by installing a LaunchAgent property list. In addition to espionage-oriented collection behavior, Calisto includes cleanup and destructive functionality, including the ability to remove files and directories from the compromised system. Its tradecraft emphasizes masquerading, hidden local staging, credential harvesting, persistence, reconnaissance, exfiltration preparation, and anti-forensic deletion on macOS systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The retrieved file is a typical Calisto decoy: it displays an icon and a message claiming that the PDF is encrypted, instructing the user to click a link to open it in Proton Drive... which then forwards them to the threat actor's phishing kit.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
“Enables a hidden ‘root’ account in macOS and sets the password specified in the Trojan code”
Bundlore can persist via a LaunchAgent. Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.
“Next, the ‘antivirus’ asks for the user’s login and password… But after receiving the credentials, the program hangs slightly before reporting that an error has occurred…”
Bundlore prompts the user for their credentials. Calisto presents an input prompt asking for the user's login and password. Cuckoo Stealer has captured passwords by prompting victims with a "macOS needs to access System Settings" GUI window. Dok prompts the user for credentials. FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. iKitten prompts the user for their credentials. Keydnap prompts the users for credentials. Proton prompts users for their credentials. RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. SILENTTRINITY's credphisher.py module can prompt a current user for their credentials. XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.
“We can see that the Trojan uses a hidden directory named .calisto to store: Keychain storage data…”
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
“Next, the ‘antivirus’ asks for the user’s login and password… But after receiving the credentials, the program hangs slightly before reporting that an error has occurred…”
Bundlore prompts the user for their credentials. Calisto presents an input prompt asking for the user's login and password. Cuckoo Stealer has captured passwords by prompting victims with a "macOS needs to access System Settings" GUI window. Dok prompts the user for credentials. FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. iKitten prompts the user for their credentials. Keydnap prompts the users for credentials. Proton prompts users for their credentials. RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. SILENTTRINITY's credphisher.py module can prompt a current user for their credentials. XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
Multiple actors and tools are described as using 7-Zip/WinRAR/zip/tar/gzip/makecab/PowerShell Compress-Archive to compress (often password-protect/encrypt) collected data prior to exfiltration (e.g., “used 7zip to archive extracted data in preparation for exfiltration”, “created password-protected RAR archives prior to exfiltration”, “used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data”).
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Calisto is a phishing kit used to create adversary-in-the-middle (AiTM) phishing pages to steal credentials, often targeting Proton services.
COLDRIVER is a Russian state-sponsored threat actor specializing in sophisticated spear phishing campaigns targeting civil society, government, academia, and NGOs. Their primary goal is credential theft via highly personalized phishing lures, often using fake encrypted PDFs and lookalike domains. They have also been observed using phishing platforms like Evilginx to bypass two-factor authentication and steal session cookies for persistent access.
Uses ifconfig to obtain victim IP addresses.
Malware that collects data from user directories.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.