Calisto

MITRE ATT&CK: S0274 View on attack.mitre.org

Aliases: Calisto

First seen
2016-01-01 00:00:00
Malware type
trojan, backdoor
Family
Malware family
Operating systems
macos
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-13 05:48:36
Profile updated
2026-07-07 14:37:35

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

Calisto is a macOS Trojan that opens a backdoor on the compromised machine. Calisto is believed to have first been developed in 2016.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Calisto (S0274). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample Calisto.dmg 2026-07-13 1

Detection coverage

  • 198 Sigma rules

Malware & tools used

  • Launch Agent (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Data from Local System (attack-pattern)
  • File Deletion (attack-pattern)
  • Launchctl (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Keychain (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Account Manipulation (attack-pattern)
  • Local Account (attack-pattern)

Reports & references

  • Kaspersky — 86543 (report)
  • MITRE ATT&CK — S0274 (report)
  • web.archive.org — 2018 073014 2512 99 (report)

External references