Star Blizzard — APT Profile
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.Also tracked as
SEABORGIUM, Callisto Group, TA446, COLDRIVER
Tools & malware
- Spica Backdoor
Vendor research
- Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns CISA
- Disrupting SEABORGIUM’s ongoing phishing operations Microsoft
- Star Blizzard increases sophistication and evasion in ongoing attacks StarBlizzard
- Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware Google TAG