| Star Blizzard | |
|---|---|
| 📧 Credential phishing emblem (illustrative) | |
| Also known as | COLDRIVER · Seaborgium · Callisto Group · TA446 · BlueCharlie |
| Formation | c. 2017 |
| Type | Advanced persistent threat (state-sponsored) |
| Purpose | Credential harvesting, Information operations |
| Target Sectors | NGOs, Journalists, Government Advisors, NATO |
| Alleged parent org. | FSB (Center 18) |
| Attribution confidence | High |
| Status | ● Highly Active |
| Notable tactics | Spear-phishing, Identity impersonation |
Star Blizzard (formerly known as COLDRIVER, Seaborgium, and Callisto Group) is a sophisticated Russian state-sponsored threat actor linked to the Federal Security Service (FSB). The group is highly specialized in spear-phishing campaigns designed to harvest credentials from high-value individuals, including journalists, former intelligence officers, and government advisors.[1]
Unlike other Russian APTs that focus on technical exploits or destructive wipers, Star Blizzard relies heavily on social engineering. Their goal is to gain direct access to personal and professional email accounts to exfiltrate sensitive documents for intelligence gathering or future “hack-and-leak” operations.[2]
Star Blizzard (Microsoft) · COLDRIVER (Google/TAG) · Seaborgium (Microsoft, legacy) · Callisto Group (F-Secure) · BlueCharlie (Recorded Future) · TA446 (Proofpoint)
Overview
Star Blizzard has been active since at least 2017. Their operations are characterized by meticulous preparation, often involving weeks of social engineering where they build rapport with targets via LinkedIn or email before delivering a malicious link. The group is particularly known for targeting NATO-aligned countries, specifically the UK and USA.[1]
Attribution
In December 2023, the UK Foreign Office and the U.S. Department of Justice formally attributed Star Blizzard to Center 18 of the Russian FSB. Two Russian nationals were indicted for their roles in a multi-year campaign to interfere in UK political processes through the theft and release of private communications.[3]
Targets and Victimology
- Journalists — Specifically those covering Russian corruption or foreign policy.
- NGOs & Think Tanks — Organizations focused on democracy, human rights, and NATO strategy.
- Government Advisors — Former military and intelligence officials with access to policy circles.
- Nuclear Laboratories — Historical targeting of U.S.-based nuclear research facilities has been documented.
Notable Campaigns
| Date | Campaign | Outcome |
|---|---|---|
| 2019 | UK-US Trade Leaks | Exfiltration of sensitive trade documents used in political influence ops. |
| 2022 | ProtonMail Phishing | Widespread targeting of activists using sophisticated fake login portals. |
| 2023 | “Very” Impersonation | Using the “very” keyword in phishing domains to target UK political figures. |
Tactics, Techniques and Procedures
The group follows a consistent lifecycle for their operations:
| Stage | Technique | Description |
|---|---|---|
| Reconnaissance | T1589 | Scraping LinkedIn and social media to find targets’ colleagues. |
| Initial Access | T1566.002 | Spear-phishing Link: Sending links to “shared documents” on legitimate cloud services. |
| Credential Access | T1557 | Adversary-in-the-Middle (AiTM): Using tools like EvilGinx to bypass Multi-Factor Authentication (MFA). |
Infrastructure and Tools
Star Blizzard makes extensive use of legitimate services to mask their activity:
- Cloud Hosting: Utilizing Microsoft OneDrive, Google Drive, and Dropbox to host “lure” PDFs.
- Domain Squatting: Registering domains that look like legitimate service providers (e.g.,
outlook-verify.com). - Web Beacons: Embedding invisible tracking pixels in emails to confirm when a target has opened a message.
References
- Microsoft Threat Intelligence, “Star Blizzard: Persistent Campaign against UK and US” (2023).
- Google Threat Analysis Group (TAG), “COLDRIVER’s evolution in credential phishing” (2022).
- UK National Cyber Security Centre (NCSC), “Advisory: Star Blizzard Phishing Tactics” (2023).
- U.S. Department of Justice, “Indictment of FSB Officers in Star Blizzard Campaign” (December 2023).
