Home/Threat Actor/Star Blizzard
Threat Actor

Star Blizzard

star_blizzard_callisto · russia · active since 2015

Star Blizzard (Callisto / Coldriver / SEABORGIUM / TA446 / Blue Charlie / G1003) is a Russian FSB Centre 18 (Information Security Centre) credential-phishing-focused cluster active since 2015 and attributed by formal coordinated December 2023 multi-government attribution (UK FCDO + UK NCSC + US DOJ + US Treasury + US State Department), with the US DOJ indictment of FSB officers Ruslan Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets and concurrent US Treasury OFAC designations and UK parallel designations placing the cluster at the highest tier of formal Russian-state-cyber attribution, responsible for sustained credential-phishing, OAuth-consent-phishing, and AitM-proxy-kit operations against UK, US, NATO-member, and Ukrainian government, parliamentary, defense, NGO, think-tank, academic, journalism, and dissident-community targets, distinguished operationally by its sustained impersonation-based phishing tradecraft, AitM proxy-kit (EvilGinx2-class) early adoption, and the 2019 hack-and-leak operation against UK-US bilateral trade-talks documents extending credential-collection into active influence operations.

russia confidence: high 27 aliases MITRE ATT&CK G1033 ↗

Profile

Star Blizzard (also tracked as Callisto Group, COLDRIVER, SEABORGIUM, TA446, Blue Charlie, TAG-53, Iron Frontier, and MITRE ATT&CK G1003) is a Russian state-sponsored credential-phishing-focused cluster attributed by formal coordinated multi-government attribution to Federal Security Service (FSB) Centre 18, the FSB Information Security Centre. The attribution at the FSB-Centre level is high- confidence following the December 7, 2023 coordinated attribution event in which the UK Foreign, Commonwealth and Development Office, UK NCSC, US Department of Justice, US Department of the Treasury OFAC, and US Department of State publicly attributed the cluster to FSB Centre 18. The DOJ concurrently unsealed a District of Columbia indictment charging two FSB-affiliated Russian nationals , Ruslan Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets, with conspiracy to commit computer fraud arising from Star Blizzard credential-phishing operations against US, UK, and NATO-allied government, defense, NGO, and academic targets. Treasury OFAC concurrently designated both individuals.

State Department issued Rewards-for-Justice bounties of up to USD 10 million per individual.

UK announced parallel designations and summoned the Russian ambassador. FSB Centre 18 is operationally distinct from FSB Centre 16. Centre 16 is the FSB's signals-intelligence directorate and runs the Turla cyber-espionage cluster and the Dragonfly / Energetic Bear ICS-targeting cluster (both already covered in this corpus as turla.yaml and dragonfly_energetic_bear.yaml respectively). Centre 18 has a substantially different mission focus on credential theft, influence-and-interference operations, and political-target surveillance rather than the technical SIGINT collection of Centre 16. The other major publicly-tracked FSB Centre 18 cluster is Gamaredon / Aqua Blizzard (already covered as gamaredon.yaml, focused on Ukraine collection), which shares the FSB Centre 18 attribution but operates a substantially different victimology, toolkit, and operational tempo than Star Blizzard. Targeting focus is overwhelmingly directed at UK, US, NATO-member, and Ukrainian government, foreign-affairs, defense, parliamentary, NGO, think-tank, academic, journalism, and dissident-community targets. The cluster has demonstrated particular sustained focus on UK parliamentarians and on Russian opposition figures in exile, including academic researchers and journalists who publish on Russian-policy topics. The cluster's targeting of UK academic and think-tank communities is dense and sustained across more than half a decade. Operationally Star Blizzard is distinguished from peer Russian- aligned clusters by being primarily credential-phishing-focused rather than malware-deploying. The cluster does not operate a signature implant family comparable to APT29's NOBELIUM toolkit or Sandworm's wiper portfolio. Instead the cluster operates a highly-disciplined credential-phishing pipeline: detailed open- source-intelligence target research, sustained impersonation of individuals from think tanks and NGOs known to the victim (using ProtonMail and other encrypted-email-service addresses that mirror legitimate names), encrypted-PDF decoy delivery, custom credential-phishing landing pages mirroring legitimate Microsoft, Google, ProtonMail, and other service login pages, AitM (adversary-in-the-middle) proxy kits including EvilGinx2 for session-token theft alongside credential capture, OAuth- application-consent phishing, and post-compromise IMAP mailbox abuse for sustained access and long-dwell surveillance. The cluster has been a consistent early adopter of AitM proxy-kit tradecraft and OAuth-consent-phishing tradecraft among publicly- tracked state-aligned clusters. A defining operational pattern is the cluster's willingness to conduct hack-and-leak operations alongside its more conventional credential-collection mission. The 2019 hack-and-leak operation targeting UK-US bilateral trade-talks documents, leaked via an anonymous online persona during the 2019 UK general election campaign and used to attempt to shape UK political discourse around healthcare-policy elements of UK-US trade negotiations, was retroactively attributed by UK government and Reuters to Star Blizzard / Callisto. The hack-and-leak tradecraft extends the cluster's typical credential-collection mission into active influence operations and is among the most operationally consequential publicly-attributed cluster activities. A handful of operational notes: First, the cluster's vendor-naming proliferation (Star Blizzard / Callisto / Coldriver / SEABORGIUM / TA446 / Blue Charlie / TAG-53) reflects a decade of fragmented pre-consolidation vendor tracking. Modern reporting should default to "Star Blizzard" as the Microsoft-canonical name.

"Callisto" remains the original cluster name and appears in some academic and policy reporting. Second, the cluster is operationally distinct from APT28 (already covered as apt28_fancybear.yaml, GRU Unit 26165 cyber-espionage), from APT29 (already covered as apt29_cozybear.yaml, SVR cyber- espionage), from Sandworm (already covered as sandworm_team.yaml , GRU Unit 74455 sabotage), from Turla (already covered as turla.yaml, FSB Centre 16 cyber-espionage), from Dragonfly (already covered as dragonfly_energetic_bear.yaml, FSB Centre 16 ICS targeting), and from Gamaredon (already covered as gamaredon.yaml, FSB Centre 18 Ukraine collection). The corpus now contains six publicly-tracked Russian state-sponsored clusters across all four major Russian state cyber services (FSB Centre 16, FSB Centre 18, GRU Unit 26165, GRU Unit 74455, SVR), with Star Blizzard being the second Centre 18 cluster. Third, the cluster's credential-phishing-only operational pattern (no signature malware implant family) is unusual among publicly- tracked state-aligned clusters at this tier. The cluster's operational discipline and tradecraft consistency rest on sustained investment in social-engineering and credential- phishing capability rather than on implant-development capability.

Aliases

27
star blizzardstar_blizzardstarblizzardcallistocallisto groupcallisto_groupcoldrivercold rivercold_riverseaborgiumsea borgiumsea_borgiumta446ta_446blue charlieblue_charliebluecharlietag-53tag_53tag53iron frontieriron_frontierdancing salomedancing_salomeg1003atk 250atk250

Notable Campaigns

8
2024-2025Continued Operations (2024-2025)
2024Continued Parliamentarian and Political-Target Phishing (2024)
2023Microsoft Star Blizzard Renaming (April 2023)
2023December 7, 2023 Coordinated Multi-Government Attribution Event
2022UK NCSC: Callisto Group Advisory (May 2022)
2022Microsoft Threat Intelligence Center: SEABORGIUM Disrupted (August 15, 2022)
2019Hack-and-Leak Operation Targeting UK-US Trade Talks (2019 disclosed 2023)
2017F-Secure: Callisto Group (April 2017)

Attribution & Reporting

Attributed by
UK Foreign Commonwealth and Development Office (FCDO)UK National Cyber Security Centre (NCSC)UK GovernmentUS Department of JusticeFBIUS Department of the Treasury OFACUS Department of StateMicrosoftMicrosoft Threat Intelligence CenterF-Secure / WithSecureMandiantRecorded Future Insikt GroupCrowdStrikeProofpointCitizen LabSekoiaCluster25CyfirmaESETSentinelOneVolexityReutersAtlantic Council DFRLab
Key reporting
reportF-Secure: Callisto Group (April 13, 2017), seminal cluster disclosure
reportUK NCSC: Callisto Group Advisory (May 2022)
reportMicrosoft Threat Intelligence Center: Disrupting SEABORGIUM's Ongoing Phishing Operations (August 15, 2022)
reportMicrosoft Threat Intelligence Center: Star Blizzard Increases Sophistication and Evasion in Ongoing Attacks (December 7, 2023)
reportUK FCDO + UK NCSC + US DOJ + US Treasury + US State Department: Coordinated Multi-Government Attribution to FSB Centre 18 (December 7, 2023), seminal formal attribution
reportUS DOJ District of Columbia Indictment: USA v. Ruslan Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets (December 7, 2023)
reportUS Treasury OFAC SDN Designations: Peretyatko and Korinets (December 7, 2023)
reportUS State Department Rewards-for-Justice: Up to USD 10 Million Per Individual (December 7, 2023)
reportCitizen Lab: Russian Disinformation by Cyber Means (June 2022)
reportRecorded Future Insikt Group: Blue Charlie / Coldriver Spear-Phishing (2022)
reportMandiant: Russia COLDRIVER Phishing (multiple years)
reportProofpoint: TA446 / COLDRIVER Tracking
reportSekoia: Coldriver UK Targeting (2023)
reportAtlantic Council DFRLab: Russia's Hack-and-Leak Operation Against UK-US Trade Documents (Retrospective Analysis)
reportReuters: Anonymous Online Persona Leaks UK-US Trade Documents (December 2019)
reportMalpedia Actor Profile: Callisto / Star Blizzard
reportMITRE ATT&CK Group G1003, Star Blizzard

Operational

State sponsor

Russia, Federal Security Service (FSB) Centre 18, also known as the FSB Information Security Centre. Attribution at the FSB-Centre level is high-confidence following the December 7, 2023 coordinated multi-government attribution event in which the UK Foreign, Commonwealth and Development Office (FCDO), UK NCSC, US Department of Justice, US Department of the Treasury OFAC, and US Department of State publicly attributed Star Blizzard / Callisto operations to FSB Centre 18. The DOJ concurrently unsealed an indictment in the District of Columbia charging two FSB-affiliated Russian nationals, Ruslan Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets, with conspiracy to commit computer fraud arising from Star Blizzard credential-phishing operations against US, UK, and NATO-allied government, defense, NGO, and academic targets. US Treasury OFAC concurrently designated both individuals.

US State Department issued Rewards-for-Justice bounties. The UK announced parallel designations and summoned the Russian ambassador. FSB Centre 18 is operationally distinct from FSB Centre 16 (the signals-intelligence directorate that runs Turla and Dragonfly, both already covered in this corpus as turla.yaml and dragonfly_energetic_bear.yaml respectively). Centre 18 has a different mission focus on credential theft, influence-and-interference operations, and political-target surveillance rather than the technical SIGINT collection of Centre 16.

Motivations
espionage, intelligence_gathering, credential_theft, influence_operations, hack_and_leak_operations, political_target_surveillance, dissident_surveillance, geopolitical_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)20/60 · 33%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)11/60 · 18%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MICROSOFT 365 OAUTH PHISHINGMICROSOFT365 OAUTH PHISHING
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin