Russian Cyber Adversary BlueCharlie Alters Infrastructure in Response to Disclosures

Teilen:

A Russia-nexus adversary has been linked to 94 new domains starting March 2023, suggesting that the group is actively modifying its infrastructure in response to public disclosures about its activities.

Cybersecurity firm Recorded Future linked the revamped infrastructure to a threat actor it tracks under the name BlueCharlie, a hacking crew that’s broadly known by the names Blue Callisto, Callisto (or Calisto), COLDRIVER, Star Blizzard (formerly SEABORGIUM), and TA446. BlueCharlie was previously given the temporary designation Threat Activity Group 53 (TAG-53).

These shifts demonstrate that these threat actors are aware of industry reporting and show a certain level of sophistication in their efforts to obfuscate or modify their activity, aiming to stymie security researchers, the company said in a technical report shared with The Hacker News.

BlueCharlie is assessed to be affiliated with Russia’s Federal Security Service (FSB), with the threat actor linked to phishing campaigns aimed at credential theft by making use of domains that masquerade as the login pages of private sector companies, nuclear research labs, and NGOs involved in Ukraine crisis relief. It’s said to be active since at least 2017.

Calisto collection activities probably contribute to Russian efforts to disrupt Kiev supply-chain for military reinforcements, Sekoia noted earlier this year. Moreover, Russian intelligence collection about identified war crime-related evidence is likely conducted to anticipate and build counter narrative on future accusations.

Source: Sekoia

Another report published by NISOS in January 2023 identified potential connections between the group’s attack infrastructure to a Russian company that contracts with governmental entities in the country.

BlueCharlie has carried out persistent phishing and credential theft campaigns that further enable intrusions and data theft, Recorded Future said, adding the actor conducts extensive reconnaissance to increase the likelihood of success of its attacks.

The latest findings reveal that BlueCharlie has moved to a new naming pattern for its domains featuring keywords related to information technology and cryptocurrency, such as cloudrootstorage[.]com, directexpressgateway[.]com, storagecryptogate[.]com, and pdfsecxcloudroute[.]com.

Seventy-eight of the 94 new domains are said to have been registered using NameCheap. Some of the other domain registrars used include Porkbun and Regway.

To mitigate threats posed by state-sponsored advanced persistent threat (APT) groups, it’s recommended that organizations implement phishing-resistant multi-factor authentication (MFA), disable macros by default in Microsoft Office, and enforce a frequent password reset policy.

While the group uses relatively common techniques to conduct attacks (such as the use of phishing and a historical reliance on open-source offensive security tools), its likely continued use of these methods, determined posture, and progressive evolution of tactics suggests the group remains formidable and capable, the company said.

 

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:13 am, Mai 24, 2025
Wetter-Symbol 13°C
L: 13° | H: 14°
light rain
Luftfeuchtigkeit: 90 %
Druck: 1012 mb
Wind: 7 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.24 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 0.43 mm 43% 13 mph 92 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 20°°C 0.93 mm 93% 16 mph 90 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 17°°C 1 mm 100% 13 mph 79 % 1018 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 20°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 97 % 1018 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 10 mph 92 % 1012 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 22°°C 0 mm 0% 13 mph 70 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
19° | 19°°C 0.43 mm 43% 9 mph 77 % 1011 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 11 mph 88 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 85 % 1009 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0.93 mm 93% 15 mph 90 % 1007 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0.25 mm 25% 16 mph 75 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,191.65
-2.28%
Ethereum(ETH)
€2,243.30
-5.23%
Fesseln(USDT)
€0.88
0.03%
XRP(XRP)
€2.06
-4.65%
Solana(SOL)
€153.95
-3.72%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.200812
-7.69%
Shiba Inu(SHIB)
€0.000012
-7.36%
Pepe(PEPE)
€0.000012
-10.93%
Peanut das Eichhörnchen(PNUT)
€0.307496
-7.39%
Nach oben scrollen