G1033: Star Blizzard
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.[1][2][3][4]
Security context for executives and security teams
G1033: Star Blizzard describes [Star Blizzard](https://attack.mitre.org/groups/G1033) is a cyber espionage and influence group originating in Russia that has been active since at least 2019. [Star Blizzard](https://attack.mitre.org/groups/G1033) campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.(Citation: Microsoft Star Blizzard August 2022)(Citation: CISA Star Bl...
Executive priority
G1033: Star Blizzard is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1033: Star Blizzard by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1033: Star Blizzard appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Star Blizzard
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1684.001 | ImpersonationSub-technique | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.[1][2][4] |
| Enterprise | T1583.001 | DomainsSub-technique | Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations.[2][3] |
| Enterprise | T1114.002 | Remote Email CollectionSub-technique | Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments.[2] |
| Enterprise | T1550.004 | Web Session CookieSub-technique | Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx.[2] |
| Enterprise | T1204.002 | Malicious FileSub-technique | Star Blizzard has lured targets into opening malicious .pdf files to deliver malware.[4] |
| Enterprise | T1608.001 | Upload MalwareSub-technique | Star Blizzard has uploaded malicious payloads to cloud storage sites.[4] |
| Enterprise | T1539 | Steal Web Session Cookie | Star Blizzard has used EvilGinx to steal the session cookies of victims directed to phishing domains.[2] |
| Enterprise | T1589 | Gather Victim Identity Information | Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts.[2] |
| Enterprise | T1585.002 | Email AccountsSub-technique | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.[1][2][4] |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | Star Blizzard has sent emails with malicious .pdf files to spread malware.[4] |
| Enterprise | T1598.002 | Spearphishing AttachmentSub-technique | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites.[1][2][3][4] |
| Enterprise | T1598.003 | Spearphishing LinkSub-technique | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites.[1][2][3][4] |
| Enterprise | T1588.002 | ToolSub-technique | Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity.[2][3] |
| Enterprise | T1583 | Acquire Infrastructure | Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.[3] |
| Enterprise | T1114.003 | Email Forwarding RuleSub-technique | Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset.[1][2] |
| Enterprise | T1585.001 | Social Media AccountsSub-technique | Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance.[1][2] |
| Enterprise | T1078 | Valid Accounts | Star Blizzard has used stolen credentials to sign into victim email accounts.[1][2] |
| Enterprise | T1586.002 | Email AccountsSub-technique | Star Blizzard has used compromised email accounts to conduct spearphishing against contacts of the original victim.[2] |
| Enterprise | T1059.007 | JavaScriptSub-technique | Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.[3] |
| Enterprise | T1593 | Search Open Websites/Domains | Star Blizzard has used open-source research to identify information about victims to use in targeting.[1][2] |
Groups, software, and campaigns
S1140: Spica
Spica is a custom backdoor written in Rust that has been used by Star Blizzard since at least 2023.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.0 | Current bundle | d0958baf5323… | ||
| 19.1 | 2.0 | Older bundle | 05ac3aa0f07c… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Microsoft Star Blizzard August 2022
Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.
Open source URL - [2]CISA Star Blizzard Advisory December 2023
CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.
Open source URL - [3]StarBlizzard
Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.
Open source URL - [4]Google TAG COLDRIVER January 2024
Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.
Open source URL - [5]COLDRIVER
(Citation: Google TAG COLDRIVER January 2024)
- [6]Callisto Group
(Citation: CISA Star Blizzard Advisory December 2023)
- [7]SEABORGIUM
(Citation: Microsoft Star Blizzard August 2022)
- [8]TA446
(Citation: CISA Star Blizzard Advisory December 2023)
- [9]mitre-attackG1033Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
