Star Blizzard

APT / StateG1033
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)20
SourceMITRE ATT&CK
0
Also known as:Blue CallistoBlueCharlieCOLD RELICCOLDRIVERCallisto GroupGOSSAMER BEARIRON FRONTIERSEABORGIUMTA446TAG-53UNC4057

Vexday analysis

Star Blizzard é um grupo russo de espionagem cibernética e influência ativo pelo menos desde 2019, rastreado pelo MITRE ATT&CK sob o identificador G1033 e também conhecido como SEABORGIUM, Callisto Group, TA446 e COLDRIVER. Suas campanhas são estreitamente alinhadas aos interesses do Estado russo e envolvem operações persistentes de phishing e roubo de credenciais contra organizações acadêmicas, de defesa, governamentais, ONGs e think tanks em países da OTAN, com ênfase nos Estados Unidos e no Reino Unido. O grupo possui 20 técnicas documentadas no MITRE ATT&CK.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity31
Impact: High
T1566.001T1059.007T1539T1550.004ENTRYInitial accessSpearphishingAttachmentEXECExecutionJavaScriptCREDCredential accessSteal Web SessionCookieLATLateral movementWeb Session CookieCOLLCollectionRemote EmailCollection

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Star Blizzard uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →