Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.007 JavaScript |
GroupStar Blizzard | Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework. |
| T1583 Acquire Infrastructure |
GroupStar Blizzard | Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails. |
| T1583.001 Domains |
GroupStar Blizzard | Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations. |
| T1588.002 Tool |
GroupStar Blizzard | Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity. |
| T1598.002 Spearphishing Attachment |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites. |
| T1598.003 Spearphishing Link |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.