3 August 2023

Russia-linked BlueCharlie APT evolves tactics as it adapts to public disclosures


Russia-linked BlueCharlie APT evolves tactics as it adapts to public disclosures

A Russia-linked threat group known as BlueCharlie, Callisto, Coldriver, Star Blizzard or Seaborgium has created roughly 100 new domains since March 2023, indicating that the group is swiftly adapting its infrastructure in response to public disclosures.

Active since 2017, the threat actor focused on cyber espionage and hack-and-leak operations. The group has been known to target individuals and organizations in North Atlantic Treaty Organization (NATO) nations, entities in Ukraine, government institutions, higher education, defense, and political sectors, non-governmental organizations (NGOs), activists, journalists, think tanks, and national laboratories.

Most recently, Recorded Future’s Insikt Group has observed BlueCharlie building new infrastructure for likely use in phishing campaigns and/or credential harvesting, which consists of 94 new domains.

“Several of the TTPs currently seen in the recent operation depart from past activity, suggesting that BlueCharlie is evolving its operations, potentially in response to public disclosures of its operations in industry reporting,” the researchers wrote in a report. “Since Insikt Group’s initial tracking of the group in September 2022, we have observed BlueCharlie engage in several TTP shifts. These shifts demonstrate that these threat actors are aware of industry reporting and show a certain level of sophistication in their efforts to obfuscate or modify their activity, aiming to stymie security researchers. Some of the changes in TTPs were also likely precipitated by the threat group’s increased awareness of operations security (OPSEC).”

Since mid-December 2022, the threat actor has changed its Tactics, Techniques and Procedures (TTPs) following the reports exposing its cyber activities. More specifically, the group changed the naming pattern for its domains using domain-naming themes related to information technology and cryptocurrency.

78 of the 94 new domains are said to have been registered using NameCheap. Some of the other domain registrars used include Porkbun and Regway.

“BlueCharlie has demonstrated the ability to adapt and evolve over time to public reporting, and will likely continue to change their TTPs based on past precedent,” the researchers commented.


Back to the list

Latest Posts

Iranian hackers target critical infrastructure, selling network access data on cybercriminal forums

Iranian hackers target critical infrastructure, selling network access data on cybercriminal forums

The advisory details tactics and techniques used by Iranian hackers to breach networks and collect valuable data.
17 October 2024
US authorities charge Sudanese brothers linked to Anonymous Sudan DDoS operation

US authorities charge Sudanese brothers linked to Anonymous Sudan DDoS operation

Anonymous Sudan carried out numerous DDoS attacks targeting US and international organizations.
17 October 2024
Nation-state hackers increasingly collaborate with cybercrooks to gather intelligence

Nation-state hackers increasingly collaborate with cybercrooks to gather intelligence

Russian state-backed hackers have been outsourcing cyberespionage tasks to cybercriminals, particularly those targeting Ukraine.
16 October 2024