Also known as: SEABORGIUM, Callisto Group, TA446, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, Callisto, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, other designations, APT28, APT34, Earth Preta, Stately Taurus, tracked as, Blue Charlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10
Star Blizzard, also known by numerous aliases including SEABORGIUM, Callisto Group, and APT28, is a highly sophisticated threat actor that aligns closely with Russian state strategic objectives. The group has engineered long‑tail phishing campaigns that compromise the email accounts of high-value contacts, leverage social engineering to deceive recipients into executing malicious attachments or links, and subsequently deploy persistent backdoor implants on compromised hosts. Their tactics extend beyond simple malware delivery; they conduct device discovery (MITRE technique T1676), enabling them to collect metadata about endpoints such as operating system versions and installed software. This reconnaissance informs further lateral movement and data‑exfiltration efforts. Recent operations have diversified into mobile platforms, with the distribution of AndroRAT via WhatsApp phishing links, indicating an adaptive approach that capitalizes on emerging communication channels. Analysis of publicly available advisories from Microsoft, CISA, and independent researchers reveals that Star Blizzard maintains a disciplined operational tempo: campaigns are often coordinated across multiple vector types (email, web, mobile) and span several weeks to months. The actor focuses on institutions with high-value research and policy influence—academia, defence ministries, think tanks, and NGOs—while expanding their coverage to include critical infrastructure sectors such as energy, telecommunications and healthcare. In summary, Star Blizzard is a well-resourced adversary whose operations combine advanced social engineering, device reconnaissance, and backdoor persistence to achieve intelligence‑gathering objectives that support Russian geopolitical aims.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Star Blizzard is a Russian state-sponsored cyber‑espionage group operating since at least 2019 that targets government, defense, academia and related industries in NATO countries. The actor employs spearphishing—often via compromised email accounts—alongside device discovery and custom backdoor implants such as CrimsonRAT (Windows) and AndroRAT (Android) to exfiltrate sensitive data. Recent activity includes a WhatsApp‑based phishing campaign aimed at further credential theft.
Goals & Targeting
Star Blizzard’s primary strategic objective is espionage aimed at acquiring state‑level and industry intelligence to advance Russia’s geopolitical influence. By infiltrating government, defence, academia and related sectors in NATO member states, the group seeks to extract policy documents, research findings, and operational data that can be leveraged for political, economic or military advantage. Their use of sophisticated techniques such as device discovery and mobile RATs indicates a long‑term persistence model designed to maintain access through successive campaigns. The actor also appears to engage in influence operations, utilizing compromised email accounts and social engineering to disseminate tailored messages or phishing content that can sway perceptions within target organizations. This dual focus on data exfiltration and subtle influence aligns with the broader Russian strategy of cyber support for foreign policy objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Star Blizzard executes campaigns with a methodical approach: initial reconnaissance via device discovery, followed by targeted spearphishing that leverages compromised email accounts and social engineering. Their operations often span multiple weeks to maintain continuity of data exfiltration while adapting to defensive postures. The actor’s past campaigns have repeatedly focused on NATO member states, targeting both public sector institutions (government ministries, defence agencies) and private sectors (academia, think tanks, critical infrastructure providers). The use of multilingual phishing vectors—including emerging platforms such as WhatsApp—demonstrates an adaptive strategy to bypass traditional email filters and exploit user trust in personal communications.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the core attribution of Star Blizzard as a Russian state‑sponsored espionage actor and its primary use of spearphishing, device discovery, and backdoor implants. Medium confidence regarding specific tool variants beyond CrimsonRAT and AndroRAT due to limited publicly available technical samples. Gaps remain in understanding the full extent of their influence operations, detailed persistence mechanisms, and potential undisclosed malware families. Continuous surveillance for new indicators is recommended.
No campaigns linked yet.
No observed data linked yet.
34
Techniques
47
Tools
0
Campaigns
44
IOCs
0
Observed Data
10
Tactics