Star Blizzard

MITRE ATT&CK: G1033 View on attack.mitre.org

Aliases: SEABORGIUM, Callisto Group, TA446, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, Callisto, Reuse Team

First seen
2019-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-21 08:31:59
Profile updated
2026-07-07 12:34:14

Targeted industries: defense-and-aerospace government-and-public-sector education-and-nonprofits

Targeted regions: country_code:us country_code:gb

Context

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.

Detection coverage

  • 1 YARA rules
  • 137 Sigma rules

Malware & tools used

  • Domains (attack-pattern)
  • Remote Email Collection (attack-pattern)
  • Web Session Cookie (attack-pattern)
  • Malicious File (attack-pattern)
  • Upload Malware (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Gather Victim Identity Information (attack-pattern)
  • Email Accounts (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Tool (attack-pattern)
  • Acquire Infrastructure (attack-pattern)
  • Email Forwarding Rule (attack-pattern)
  • Social Media Accounts (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Email Accounts (attack-pattern)
  • JavaScript (attack-pattern)
  • Search Open Websites/Domains (attack-pattern)
  • Linked Devices (attack-pattern)
  • Impersonation (attack-pattern)
  • Spica (malware)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • blog.google — Continued Cyber Activity In Eastern Europe Observed By Tag (report)
  • services.google.com — Google Fog Of War Research Report (report)
  • web.archive.org — Callisto Group (report)
  • blog.google — Tracking Cyber Activity Eastern Europe (report)
  • blog.google — Update On Cyber Activity In Eastern Europe (report)
  • Microsoft — Disrupting Seaborgiums Ongoing Phishing Operations (report)
  • blog.sekoia.io — Calisto Continues Its Credential Harvesting Campaign (report)
  • recordedfuture.com — Bluecharlie Previously Tracked As Tag 53 Continues To Deploy New Infrastructure In 2023 (report)
  • Microsoft — Star Blizzard Increases Sophistication And Evasion In Ongoing Attacks (report)
  • go.recordedfuture.com — Cta 2022 1205 (report)
  • pwc.com — Blue Callisto Orbits Around Us (report)
  • ncsc.gov.uk — Advisory Russian Fsb Cyber Actor Star Blizzard Continues Worldwide Spear Sphishing Campaigns (report)
  • cloud.google.com — Cyber Threats Global Elections (report)
  • cloud.google.com — Cyber Threats 2024 Paris Olympics (report)
  • blog.google — Google Tag Coldriver Russian Phishing Malware (report)
  • citizenlab.ca — Sophisticated Phishing Targets Russias Perceived Enemies Around The Globe (report)
  • gov.uk — Uk Exposes Attempted Russian Cyber Interference In Politics And Democratic Processes (report)
  • pwc.com — Coldwastrel Space (report)
  • citizenlab.ca — Disrupting Coldriver (report)
  • Microsoft — Protecting Democratic Institutions From Cyber Threats (report)
  • justice.gov — Justice Department Disrupts Russian Intelligence Spear Phishing Efforts (report)
  • justice.gov — Two Russian Nationals Working Russias Federal Security Service Charged Global Computer (report)
  • justice.gov — Dl (report)
  • noticeofpleadings.com — Starblizzard (report)

External references