Netskope Threat Labs

Calisto

ATP Sandbox Adv. HeuristicsAV

Calisto is macOS malware that steals credentials and provides backdoor access to compromised machines. It harvests user account data, browser information, and stored passwords, and it can grant operators remote access to the infected system. Researchers first identified the family in 2016 and 2017 campaigns, and although its activity faded, its source code circulated underground and kept variants alive in the wild.

First seen
January 2022
Last seen
October 2026

15 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1217Browser Information Discovery

TA0009 Collection

TA0011 Command and Control

  • T1105Ingress Tool Transfer
Alert Name
Image.Backdoor.Calisto
JS.Heur.Calisto.2.1.0CE22005.Gen
JS.Heur.Calisto.2.1.20D6A6E9.Gen
JS.Heur.Calisto.2.1.27BDA26E.Gen
JS.Heur.Calisto.2.1.2B8CB247.Gen
JS.Heur.Calisto.2.1.33637FA1.Gen
JS.Heur.Calisto.2.1.368354C7.Gen
JS.Heur.Calisto.2.1.64D0BB59.Gen
JS.Heur.Calisto.2.1.6D220C9A.Gen
JS.Heur.Calisto.2.1.71FA5A89.Gen