CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupStar Blizzard | Star Blizzard has used stolen credentials to sign into victim email accounts. |
| T1114.002 Remote Email Collection |
GroupStar Blizzard | Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments. |
| T1114.003 Email Forwarding Rule |
GroupStar Blizzard | Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset. |
| T1539 Steal Web Session Cookie |
GroupStar Blizzard | Star Blizzard has used EvilGinx to steal the session cookies of victims directed to |
| T1550.004 Web Session Cookie |
GroupStar Blizzard | Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx. |
| T1583.001 Domains |
GroupStar Blizzard | Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations. |
| T1585.001 Social Media Accounts |
GroupStar Blizzard | Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance. |
| T1585.002 Email Accounts |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
| T1586.002 Email Accounts |
GroupStar Blizzard | Star Blizzard has used compromised email accounts to conduct spearphishing against |
| T1588.002 Tool |
GroupStar Blizzard | Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity. |
| T1589 Gather Victim Identity Information |
GroupStar Blizzard | Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts. |
| T1593 Search Open Websites/Domains |
GroupStar Blizzard | Star Blizzard has used open-source research to identify information about victims to use in targeting. |
| T1598.002 Spearphishing Attachment |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites. |
| T1598.003 Spearphishing Link |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites. |
| T1684.001 Impersonation |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.