NEW: Group Profiler — instant APT intel lookup. Try it →

Star Blizzard

G1033 Russia MITRE ATT&CK →

Also known as: SEABORGIUM · Callisto Group · TA446 · COLDRIVER

Overview

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.

Naming & attribution

Star Blizzard is tracked under 5 names across the industry. It uses 20 documented ATT&CK techniques — more than 53% of the 174 groups tracked here. Activity attributed since at least 2019.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
SEABORGIUMMicrosoft Threat Intelligence
Callisto GroupCISA, et al
TA446CISA, et al
COLDRIVERShields, W

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1550.004 Web Session Cookie — used by 1 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • IndigoZebra China — 5 shared techniques (23% overlap)
  • Silent Librarian — 6 shared techniques (22% overlap)
  • EXOTIC LILY — 6 shared techniques (21% overlap)
  • APT-C-36 — 9 shared techniques (18% overlap)
  • WIRTE — 7 shared techniques (18% overlap)
  • CURIUM Iran — 6 shared techniques (18% overlap)

Malware families with current indicators

One family attributed to Star Blizzard, carrying 4 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • SPICA 4 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Government · Journalists · Military · Think Tanks

TTPs — 20 techniques across 8 tactics

Resource Development

Initial Access

Execution

Stealth

Credential Access

Lateral Movement

Collection

Tools & malware (1)

Spica

Reporting (3)