Threat group.View on attack.mitre.org
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.
| Technique | Procedure example |
|---|---|
| T1059.007 JavaScript |
Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework. |
| T1078 Valid Accounts |
Star Blizzard has used stolen credentials to sign into victim email accounts. |
| T1114.002 Remote Email Collection |
Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments. |
| T1114.003 Email Forwarding Rule |
Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset. |
| T1204.002 Malicious File |
Star Blizzard has lured targets into opening malicious .pdf files to deliver malware. |
| T1539 Steal Web Session Cookie |
Star Blizzard has used EvilGinx to steal the session cookies of victims directed to |
| T1550.004 Web Session Cookie |
Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx. |
| T1566.001 Spearphishing Attachment |
Star Blizzard has sent emails with malicious .pdf files to spread malware. |
| T1583 Acquire Infrastructure |
Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails. |
| T1583.001 Domains |
Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations. |
| T1585.001 Social Media Accounts |
Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance. |
| T1585.002 Email Accounts |
Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
| T1586.002 Email Accounts |
Star Blizzard has used compromised email accounts to conduct spearphishing against |
| T1588.002 Tool |
Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity. |
| T1589 Gather Victim Identity Information |
Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.