Skip to content

Hide Navigation Hide TOC

TAG-53 (e5865ca1-ec95-43e2-954a-d0f3507a9747)

A Russia-linked threat actor tracked as TAG-53 is running phishing campaigns impersonating various defense, aerospace, and logistic companies, according to The Record by Recorded Future. Recorded Future’s Insikt Group identified overlaps with a threat actor tracked by other companies as Callisto Group, COLDRIVER, and SEABORGIUM.

Cluster A Galaxy A Cluster B Galaxy B Level
TAG-53 (e5865ca1-ec95-43e2-954a-d0f3507a9747) Threat Actor Callisto (fbd279ab-c095-48dc-ba48-4bece3dd5b0f) Threat Actor 1
Star Blizzard (06630ccd-98ed-5aec-8083-e04c894bd2d6) Microsoft Activity Group actor Callisto (fbd279ab-c095-48dc-ba48-4bece3dd5b0f) Threat Actor 2