Star Blizzard — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    Star Blizzard

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    Star Blizzard
    📧
    Credential phishing emblem (illustrative)
    Also known asCOLDRIVER · Seaborgium · Callisto Group · TA446 · BlueCharlie
    Formationc. 2017
    TypeAdvanced persistent threat (state-sponsored)
    PurposeCredential harvesting, Information operations
    Target SectorsNGOs, Journalists, Government Advisors, NATO
    Alleged parent org.FSB (Center 18)
    Attribution confidenceHigh
    Status● Highly Active
    Notable tacticsSpear-phishing, Identity impersonation

    Star Blizzard (formerly known as COLDRIVER, Seaborgium, and Callisto Group) is a sophisticated Russian state-sponsored threat actor linked to the Federal Security Service (FSB). The group is highly specialized in spear-phishing campaigns designed to harvest credentials from high-value individuals, including journalists, former intelligence officers, and government advisors.[1]

    Unlike other Russian APTs that focus on technical exploits or destructive wipers, Star Blizzard relies heavily on social engineering. Their goal is to gain direct access to personal and professional email accounts to exfiltrate sensitive documents for intelligence gathering or future “hack-and-leak” operations.[2]

    Aliases used by other vendors:
    Star Blizzard (Microsoft) · COLDRIVER (Google/TAG) · Seaborgium (Microsoft, legacy) · Callisto Group (F-Secure) · BlueCharlie (Recorded Future) · TA446 (Proofpoint)

    Overview

    Star Blizzard has been active since at least 2017. Their operations are characterized by meticulous preparation, often involving weeks of social engineering where they build rapport with targets via LinkedIn or email before delivering a malicious link. The group is particularly known for targeting NATO-aligned countries, specifically the UK and USA.[1]

    Attribution

    In December 2023, the UK Foreign Office and the U.S. Department of Justice formally attributed Star Blizzard to Center 18 of the Russian FSB. Two Russian nationals were indicted for their roles in a multi-year campaign to interfere in UK political processes through the theft and release of private communications.[3]

    “Star Blizzard doesn’t just hack systems; they hack people. Their ability to impersonate trusted colleagues and experts makes them one of the most effective espionage units in the Russian toolkit.”
    — Cybersecurity Analyst Synthesis, 2024[4]

    Targets and Victimology

    • Journalists — Specifically those covering Russian corruption or foreign policy.
    • NGOs & Think Tanks — Organizations focused on democracy, human rights, and NATO strategy.
    • Government Advisors — Former military and intelligence officials with access to policy circles.
    • Nuclear Laboratories — Historical targeting of U.S.-based nuclear research facilities has been documented.

    Notable Campaigns

    DateCampaignOutcome
    2019UK-US Trade LeaksExfiltration of sensitive trade documents used in political influence ops.
    2022ProtonMail PhishingWidespread targeting of activists using sophisticated fake login portals.
    2023“Very” ImpersonationUsing the “very” keyword in phishing domains to target UK political figures.

    Tactics, Techniques and Procedures

    The group follows a consistent lifecycle for their operations:

    StageTechniqueDescription
    ReconnaissanceT1589Scraping LinkedIn and social media to find targets’ colleagues.
    Initial AccessT1566.002Spear-phishing Link: Sending links to “shared documents” on legitimate cloud services.
    Credential AccessT1557Adversary-in-the-Middle (AiTM): Using tools like EvilGinx to bypass Multi-Factor Authentication (MFA).

    Infrastructure and Tools

    Star Blizzard makes extensive use of legitimate services to mask their activity:

    • Cloud Hosting: Utilizing Microsoft OneDrive, Google Drive, and Dropbox to host “lure” PDFs.
    • Domain Squatting: Registering domains that look like legitimate service providers (e.g., outlook-verify.com).
    • Web Beacons: Embedding invisible tracking pixels in emails to confirm when a target has opened a message.

    References

    1. Microsoft Threat Intelligence, “Star Blizzard: Persistent Campaign against UK and US” (2023).
    2. Google Threat Analysis Group (TAG), “COLDRIVER’s evolution in credential phishing” (2022).
    3. UK National Cyber Security Centre (NCSC), “Advisory: Star Blizzard Phishing Tactics” (2023).
    4. U.S. Department of Justice, “Indictment of FSB Officers in Star Blizzard Campaign” (December 2023).
    Categories: Advanced persistent threats · Russian state-sponsored hacking · FSB · Phishing · Information Operations
    This page was last synced August 2026. Content reflects public intelligence disclosures.