Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Star Blizzard

Also known as: SEABORGIUM, Callisto Group, TA446, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, Callisto, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, other designations, APT28, APT34, Earth Preta, Stately Taurus, tracked as, Blue Charlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10

Description

Star Blizzard, also known by numerous aliases including SEABORGIUM, Callisto Group, and APT28, is a highly sophisticated threat actor that aligns closely with Russian state strategic objectives. The group has engineered long‑tail phishing campaigns that compromise the email accounts of high-value contacts, leverage social engineering to deceive recipients into executing malicious attachments or links, and subsequently deploy persistent backdoor implants on compromised hosts. Their tactics extend beyond simple malware delivery; they conduct device discovery (MITRE technique T1676), enabling them to collect metadata about endpoints such as operating system versions and installed software. This reconnaissance informs further lateral movement and data‑exfiltration efforts. Recent operations have diversified into mobile platforms, with the distribution of AndroRAT via WhatsApp phishing links, indicating an adaptive approach that capitalizes on emerging communication channels. Analysis of publicly available advisories from Microsoft, CISA, and independent researchers reveals that Star Blizzard maintains a disciplined operational tempo: campaigns are often coordinated across multiple vector types (email, web, mobile) and span several weeks to months. The actor focuses on institutions with high-value research and policy influence—academia, defence ministries, think tanks, and NGOs—while expanding their coverage to include critical infrastructure sectors such as energy, telecommunications and healthcare. In summary, Star Blizzard is a well-resourced adversary whose operations combine advanced social engineering, device reconnaissance, and backdoor persistence to achieve intelligence‑gathering objectives that support Russian geopolitical aims.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Financial services
Education
Non profit
Healthcare
Manufacturing
Think tank
Energy
Media
Critical infrastructure
Hospitality
Aerospace
Pharmaceutical
Aviation
Transportation
Retail
Chemical
Maritime
Legal services
Information technology
Mining
Gaming
Nuclear
Entertainment
Utilities
Oil gas
Construction

Targeted Countries / Regions

US
CN
RU
UA
IL
AE
VN
PK
IR
GB
JP
BY
IN
TW
KR
SA
PL
AU
TR
DE
LB
KZ
SG
IT
FR
MX
ES
CA
IQ
RO
NG
KP
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Star Blizzard is a Russian state-sponsored cyber‑espionage group operating since at least 2019 that targets government, defense, academia and related industries in NATO countries. The actor employs spearphishing—often via compromised email accounts—alongside device discovery and custom backdoor implants such as CrimsonRAT (Windows) and AndroRAT (Android) to exfiltrate sensitive data. Recent activity includes a WhatsApp‑based phishing campaign aimed at further credential theft.

Goals & Targeting

Star Blizzard’s primary strategic objective is espionage aimed at acquiring state‑level and industry intelligence to advance Russia’s geopolitical influence. By infiltrating government, defence, academia and related sectors in NATO member states, the group seeks to extract policy documents, research findings, and operational data that can be leveraged for political, economic or military advantage. Their use of sophisticated techniques such as device discovery and mobile RATs indicates a long‑term persistence model designed to maintain access through successive campaigns. The actor also appears to engage in influence operations, utilizing compromised email accounts and social engineering to disseminate tailored messages or phishing content that can sway perceptions within target organizations. This dual focus on data exfiltration and subtle influence aligns with the broader Russian strategy of cyber support for foreign policy objectives.

Enhanced Description

Key Capabilities

  • Spearphishing via compromised email accounts
  • Social engineering and impersonation attacks
  • Device discovery (T1676) to map endpoint attributes
  • Deployment of custom persistent backdoor implants (CrimsonRAT, AndroRAT)
  • Credential theft and exfiltration
  • WhatsApp-based phishing campaigns targeting mobile devices

MITRE ATT&CK Tactics

Discovery
Initial Access
Execution
Credential Access
Collection

ATT&CK Techniques

T1059
T1078
T1114
T1114.002
T1114.003
T1134
T1204
T1204.002
T1539
T1550
T1550.004
T1583
T1585
T1585.001
T1585.002
T1586
T1586.002
T1588
T1588.002
T1593
T1598
T1598.002
T1598.003
T1608
T1608.001
T1684
T1684.001
T1676

Software / Tooling

CrimsonRAT
AndroRAT
Machete
Akira
PowerShell

Campaigns & Victims

Star Blizzard executes campaigns with a methodical approach: initial reconnaissance via device discovery, followed by targeted spearphishing that leverages compromised email accounts and social engineering. Their operations often span multiple weeks to maintain continuity of data exfiltration while adapting to defensive postures. The actor’s past campaigns have repeatedly focused on NATO member states, targeting both public sector institutions (government ministries, defence agencies) and private sectors (academia, think tanks, critical infrastructure providers). The use of multilingual phishing vectors—including emerging platforms such as WhatsApp—demonstrates an adaptive strategy to bypass traditional email filters and exploit user trust in personal communications.

IOC Patterns

  • Domain indicators with temporary or disposable DNS names (e.g., .TEMP.*)
  • Compromised email account usage for spearphishing
  • WhatsApp link phishing targeting mobile users
  • Email forwarding rules manipulated via T1114 collection
  • Suspicious domain registrations linked to known actors

Recommended Actions

  • Enforce multi‑factor authentication on all user and privileged accounts, especially those with access to sensitive data.
  • Implement advanced email security (anti‑phishing, attachment sandboxing, link scanning) and harden defenses against spearphishing and WhatsApp‑based social engineering.
  • Deploy endpoint detection & response solutions capable of detecting and blocking known backdoor implants like CrimsonRAT and AndroRAT. Regularly monitor network traffic for device discovery indicators (e.g., suspicious SMB or RPC queries) and block known malicious domains using threat intelligence feeds. Audit email forwarding rules and mailbox permissions to detect unauthorized rule creation.
  • Maintain timely patch management for operating systems, Microsoft Exchange, and mobile devices to close exploitation vectors used by these actors.
  • Conduct ongoing user awareness training focused on phishing recognition across email, messaging apps and social platforms.
  • Segment critical infrastructure networks and enforce least privilege access controls to limit lateral movement should an implant be compromised.

Suggested Tags

Russia
State-sponsored
Cyber espionage
Phishing
Backdoor
Mobile RAT
APT28
Seaborgium
Callisto Group
Spearphishing
Credential theft
WhatsApp targeting
NATO influence campaign
Star Blizzard

Confidence Assessment

High confidence in the core attribution of Star Blizzard as a Russian state‑sponsored espionage actor and its primary use of spearphishing, device discovery, and backdoor implants. Medium confidence regarding specific tool variants beyond CrimsonRAT and AndroRAT due to limited publicly available technical samples. Gaps remain in understanding the full extent of their influence operations, detailed persistence mechanisms, and potential undisclosed malware families. Continuous surveillance for new indicators is recommended.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
5 techniques
Resource Development
11 techniques
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. CISA Star Blizzard Advisory December 2023 — CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.
  2. Microsoft Star Blizzard August 2022 — Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.
  3. StarBlizzard — Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.
  4. Google TAG COLDRIVER January 2024 — Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.
  5. www.eset.com — Cited by web research for: APT28
  6. attack.mitre.org — Cited by web research for: T1059
  7. attack.mitre.org — Cited by web research for: Akira
  8. https://www.securityweek.com/russian-apt-switches-to-new-backdoor-after-malware-exposed-by-researchers/ — Cited by AI analysis.
  9. https://www.cybercom.mil/Media/News/Article/3610373/us-allies-highlight-russian-state-cyber-actor- — Cited by AI analysis.
  10. https://industrialcyber.co/reports/iranian-state-sponsored-hackers-exploit-microsoft-exchange-for — Cited by AI analysis.
  11. https://www.microsoft.com/en-us/security/blog/2025/01/16/new-star-blizzard-spear-phishing-campaign-target — Cited by AI analysis.
  12. https://attack.mitre.org/techniques/T1676/ — Cited by AI analysis.
  13. https://www.cisa.gov/news-events/alerts/2023/12/07/cisa-and-international-partners-release-advisory-russia-based- — Cited by AI analysis.

Intel Summary

34

Techniques

47

Tools

0

Campaigns

44

IOCs

0

Observed Data

10

Tactics

Tags

APT
Phishing
Data Exfiltration
Government Targeting
Russia
State-sponsored
Cyber espionage
Backdoor
Mobile RAT
APT28
Seaborgium
Callisto Group
Spearphishing
Credential theft
WhatsApp targeting
NATO influence campaign
Star Blizzard

Details

MITRE ID
G1033
Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--9b36c218-4d80-4ec6-a68d-cc2886bbe410
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.