FORENSIA

THREAT_ACTOR · G1033

Star Blizzard

Also known as: Star Blizzard, SEABORGIUM, Callisto Group, TA446, COLDRIVER

Profile

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.

MITRE ATT&CK ↗

Techniques

20 ATT&CK techniques attributed to this actor.

Software

1 malware/tools attributed to this actor.

Spica

Related corpus activity

8,581 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Star Blizzard.