Calisto
MITRE ATT&CK: S0274 View on attack.mitre.org
Aliases: Calisto
- First seen
- 2016-01-01 00:00:00
- Malware type
- trojan, backdoor
- Family
- Malware family
- Operating systems
- macos
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-07-13 05:48:36
- Profile updated
- 2026-07-07 14:37:35
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
Calisto is a macOS Trojan that opens a backdoor on the compromised machine. Calisto is believed to have first been developed in 2016.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Calisto (S0274). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | Calisto.dmg | 2026-07-13 | 1 |
Detection coverage
- 198 Sigma rules
Malware & tools used
- Launch Agent (attack-pattern)
- Browser Information Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- GUI Input Capture (attack-pattern)
- Data from Local System (attack-pattern)
- File Deletion (attack-pattern)
- Launchctl (attack-pattern)
- Archive via Utility (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Keychain (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Local Data Staging (attack-pattern)
- Account Manipulation (attack-pattern)
- Local Account (attack-pattern)
Reports & references
- Kaspersky — 86543 (report)
- MITRE ATT&CK — S0274 (report)
- web.archive.org — 2018 073014 2512 99 (report)