🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
STAR BLIZZARD (SEABORGIUM)

/actor/star-blizzard-seaborgium/  ·  0 intel reports

Year Established
2017
Attribution
Russia (FSB Centre 18)
Motivation
Espionage, Influence Operations
Modus Operandi (MO)
Spear-phishing, credential harvesting, NATO and civil society targeting, document theft for influence operations
Primary Aliases
Seaborgium, Callisto Group, TA446, COLDRIVER, Dancing Salome

Star Blizzard, formerly tracked by Microsoft as Seaborgium and by other researchers as the Callisto Group, is a Russian Federal Security Service (FSB) threat actor attributed to the FSB's Centre 18 unit. The group specialises in credential harvesting and long-term spear-phishing campaigns against Western government officials, defence policy experts, journalists, think tanks, and civil society organisations , particularly those focused on Russia, Ukraine, and NATO affairs.

Star Blizzard's hallmark technique involves creating highly convincing impersonation accounts of trusted individuals , colleagues, conference organisers, or government officials , to trick targets into clicking malicious links that redirect to credential harvesting pages. The group invests significant time in building rapport with targets before delivering the phishing payload, demonstrating sophisticated social engineering capabilities.

The group has been linked to several significant intelligence operations, including the theft of sensitive internal communications from UK political figures and the attempted compromise of US government email accounts. Perhaps most notably, Star Blizzard has been associated with stealing private correspondence from UK-US trade negotiation participants, which was subsequently leaked online to generate political controversy , demonstrating their role in Russian information operations beyond pure intelligence collection.

In October 2024, Microsoft and the US Department of Justice jointly seized over 100 internet domains used by Star Blizzard for spear-phishing infrastructure, significantly disrupting the group's operational capabilities. The FSB's continued use of Star Blizzard to target civil society and democratic institutions underscores Russia's broad approach to using cyber operations as a tool of political warfare against Western democracies.

Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Star Blizzard (Seaborgium) executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles