ATT&CKReferencesMicrosoft Star Blizzard August 2022

Microsoft Star Blizzard August 2022

Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupStar Blizzard

Star Blizzard has used stolen credentials to sign into victim email accounts.

T1114.003
Email Forwarding Rule
GroupStar Blizzard

Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset.

T1585.001
Social Media Accounts
GroupStar Blizzard

Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance.

T1585.002
Email Accounts
GroupStar Blizzard

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

T1593
Search Open Websites/Domains
GroupStar Blizzard

Star Blizzard has used open-source research to identify information about victims to use in targeting.

T1598.002
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites.

T1598.003
Spearphishing Link
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites.

T1684.001
Impersonation
GroupStar Blizzard

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.