ATT&CKGroupsStar Blizzard

Star Blizzard

G1033

Threat group.View on attack.mitre.org

About this group

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1059.007
JavaScript

Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.

T1078
Valid Accounts

Star Blizzard has used stolen credentials to sign into victim email accounts.

T1114.002
Remote Email Collection

Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments.

T1114.003
Email Forwarding Rule

Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset.

T1204.002
Malicious File

Star Blizzard has lured targets into opening malicious .pdf files to deliver malware.

T1539
Steal Web Session Cookie

Star Blizzard has used EvilGinx to steal the session cookies of victims directed to
phishing domains.

T1550.004
Web Session Cookie

Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx.

T1566.001
Spearphishing Attachment

Star Blizzard has sent emails with malicious .pdf files to spread malware.

T1583
Acquire Infrastructure

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.

T1583.001
Domains

Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations.

T1585.001
Social Media Accounts

Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance.

T1585.002
Email Accounts

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

T1586.002
Email Accounts

Star Blizzard has used compromised email accounts to conduct spearphishing against
contacts of the original victim.

T1588.002
Tool

Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity.

T1589
Gather Victim Identity Information

Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts.

View all 20 procedure examples

Software1

Campaigns0

None recorded.

References4

  1. CISA Star Blizzard Advisory December 2023 Open source
    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.
  2. Google TAG COLDRIVER January 2024 Open source
    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.
  3. Microsoft Star Blizzard August 2022 Open source
    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.
  4. StarBlizzard Open source
    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.