ATT&CKReferencesStarBlizzard

StarBlizzard

Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059.007
JavaScript
GroupStar Blizzard

Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.

T1583
Acquire Infrastructure
GroupStar Blizzard

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.

T1583.001
Domains
GroupStar Blizzard

Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations.

T1588.002
Tool
GroupStar Blizzard

Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity.

T1598.002
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites.

T1598.003
Spearphishing Link
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.