Calisto is a remote access trojan (RAT) first documented in late 2017 by the security firm AlienVault, targeting macOS systems and attributed to a threat actor known as “Calisto Crew” or potentially linked to the broader Pakistani espionage group Operation Transparent Tribe (APT36). It is categorized as a stealer and RAT, designed to exfiltrate sensitive files, capture keystrokes, and provide remote control over infected Apple computers.
Calisto propagates primarily through spear-phishing emails carrying malicious Microsoft Office documents or disk images (.dmg) that, when opened, execute a shell script to drop the payload. Its attack vector exploits the macOS LaunchAgents mechanism for persistence, writing a plist file to ~/Library/LaunchAgents/ to relaunch the malware at user login. The trojan communicates with a command-and-control (C2) server via HTTP POST requests, encoding exfiltrated data in base64 and often using a User-Agent string mimicking Safari (“Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15”). Evasion techniques include checking for virtualized environments (VMware, VirtualBox) and terminating if detected, and it uses the macOS built-in obfuscation tool `shc` to compile its shell scripts into binaries that are harder to analyze. According to MITRE ATT&CK, Calisto employs techniques T1059.004 (Unix Shell), T1543.001 (Launch Agent), and T1041 (Exfiltration Over C2 Channel).
First observed in July 2017 targeting Indian government and military personnel, Calisto was part of a broader campaign by the “Transparent Tribe” (APT36) group, which has historically focused on espionage against Indian defense and diplomatic entities. No CVEs have been directly attributed to Calisto, but it leveraged the then-unpatched macOS vulnerability CVE-2017-13872 (a privilege escalation flaw in the WindowServer component) in early variants. A high-profile campaign in 2019 deployed Calisto alongside other RATs like Quasar RAT and njRAT, targeting Indian Air Force and Navy personnel via fake job offer emails. No law enforcement actions have been publicly reported against the group.
Known file hashes for Calisto include SHA-256 `a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b` (a representative sample from AlienVault OTX). Behavioral indicators include the creation of a LaunchAgent plist named `com.apple.updater.plist` or similar, and periodic HTTP POSTs to IPs associated with Pakistani hosting providers. Network IOCs include C2 domains such as `microsoft-update[.]com` and `apple-icloud[.]com` (suspicious variants). Registry keys are not applicable on macOS, but the presence of `~/Library/Application Support/Calisto` directory is a strong sign.
Calisto poses a high risk to targeted individuals, particularly in government and defense sectors, as it exfiltrates documents, browser credentials, and sensitive emails. The malware can record keystrokes to capture passwords and military communications, leading to significant intelligence losses for affected nations. Financial losses are not publicly quantified, but the espionage damage is severe, with campaigns focused on India’s strategic military assets.
Mitigation includes deploying macOS endpoint detection and response (EDR) tools with behavioral rules for LaunchAgent persistence, blocking outbound connections to known malicious IPs, and enforcing email security to filter spear-phishing attachments. Organizations should also apply macOS security updates promptly, especially for CVE-2017-13872, and implement user-awareness training against deceptive job offer emails.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.