LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1033: Star Blizzard

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.[1][2][3][4]

EnterpriseG1033GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Star Blizzard matters because ATT&CK describes it as a Russia-origin cyber espionage and influence group associated with persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, especially the US and UK. For leaders, the practical issue is not just malware: the relationship set points to identity compromise, email collection, session-cookie abuse, impersonation, and infrastructure preparation. That makes cloud email, identity controls, executive/VIP protection, and phishing response readiness central to resilience.

Executive priority

Prioritize this as an identity and communications-risk scenario. Executives should ask whether the organization can quickly prove who accessed cloud email, whether suspicious forwarding rules or linked devices would be noticed, whether session theft can be investigated, and whether high-risk staff have tailored anti-phishing support. The business value is stronger incident decision-making: faster containment of compromised accounts, better evidence for audit and regulatory inquiries, and reduced risk of sensitive email or messaging exposure.

Technical view

ATT&CK does not provide a detection section for Star Blizzard, so validation should be built from the related behaviors: spearphishing attachments and links, impersonation, credential or session abuse, valid-account use, remote email collection, email forwarding rules, and use of Spica, a Windows custom backdoor. SOC and IR teams should test whether they can correlate pre-compromise indicators such as suspicious domains, email accounts, and social personas with post-compromise identity events such as anomalous cloud email access, new forwarding rules, unusual mailbox searches, impossible or atypical sign-ins, session reuse, and endpoint execution from malicious files or JavaScript.

Likely telemetry

  • Email security logs for inbound spearphishing links, attachments, sender impersonation, and user reporting outcomes
  • Identity provider and SaaS authentication logs, including successful logins, MFA events where available, session creation, and anomalous geolocation or device context
  • Cloud email audit logs for mailbox access, search activity, OAuth or session activity where available, and remote email collection patterns
  • Mailbox rule and forwarding configuration changes, especially external forwarding or hidden/unusual rules
  • Browser, SaaS, and identity telemetry relevant to web session cookie theft or reuse, where collected

Detection direction

  • Do not rely on a single phishing alert; tune for chains that connect impersonation, attachment/link delivery, credential submission or session anomaly, and subsequent mailbox access.
  • Validate that cloud email audit logging captures forwarding rule creation, external forwarding, mailbox access, and unusual collection behavior; these are key relationship-driven behaviors for this group object.
  • Review false positives carefully for researchers, executives, policy staff, and external-affairs teams who may legitimately interact with unfamiliar contacts, NGOs, think tanks, or academic domains.
  • Hunt for valid-account activity that looks normal in isolation but is unusual by user, device, location, time, mailbox volume, or session characteristics.
  • If Windows endpoints are in scope, confirm visibility for malicious file execution, script execution, and indicators associated with the related Spica software; ATT&CK lists Spica as Windows-related.

Mitigation priorities

  • Start with identity hardening for high-risk users: strong MFA, conditional access principles, rapid account disablement/reset processes, and session revocation procedures where supported.
  • Harden cloud email: restrict or monitor external forwarding, alert on suspicious mailbox rules, preserve mailbox audit logs, and document evidence collection steps for IR.
  • Improve phishing resilience with targeted user reporting, executive/VIP workflows, and controls for suspicious attachments, links, impersonation, and newly registered or lookalike domains.
  • Prepare IR playbooks for account compromise that include mailbox review, forwarding-rule removal, session/token revocation, endpoint triage for malicious files or scripts, and communications handling.
  • Reduce reconnaissance exposure where feasible by reviewing public identity information for sensitive roles and by briefing likely targets on impersonation and social-media/email persona risks.
Additional notes and limits

The supplied ATT&CK object is a group profile, not a complete intrusion playbook. The strongest decision value comes from the relationships: Star Blizzard is linked to phishing for information, spearphishing, impersonation, valid-account use, web session cookies, remote email collection, email forwarding rules, resource development, and Spica. These relationships point defenders toward identity, SaaS email, endpoint execution, and pre-attack infrastructure visibility rather than only perimeter blocking.

Official detection text is not provided, and the group object itself lists no platforms or tactics. Platform references above are derived only from related techniques/software, so local applicability depends on the organization’s actual identity provider, email platform, endpoint estate, SaaS usage, mobile/messaging apps, and logging configuration. No claim is made that any specific organization is targeted or that existing controls will detect this behavior.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Star Blizzard

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

20 rows
DomainIDNameRelationship / procedure
EnterpriseT1684.001ImpersonationSub-technique

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.[1][2][4]

EnterpriseT1583.001DomainsSub-technique

Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations.[2][3]

EnterpriseT1114.002Remote Email CollectionSub-technique

Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments.[2]

EnterpriseT1550.004Web Session CookieSub-technique

Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx.[2]

EnterpriseT1204.002Malicious FileSub-technique

Star Blizzard has lured targets into opening malicious .pdf files to deliver malware.[4]

EnterpriseT1608.001Upload MalwareSub-technique

Star Blizzard has uploaded malicious payloads to cloud storage sites.[4]

EnterpriseT1539Steal Web Session Cookie

Star Blizzard has used EvilGinx to steal the session cookies of victims directed to phishing domains.[2]

EnterpriseT1589Gather Victim Identity Information

Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts.[2]

EnterpriseT1585.002Email AccountsSub-technique

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.[1][2][4]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Star Blizzard has sent emails with malicious .pdf files to spread malware.[4]

EnterpriseT1598.002Spearphishing AttachmentSub-technique

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites.[1][2][3][4]

EnterpriseT1598.003Spearphishing LinkSub-technique

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites.[1][2][3][4]

EnterpriseT1588.002ToolSub-technique

Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity.[2][3]

EnterpriseT1583Acquire Infrastructure

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.[3]

EnterpriseT1114.003Email Forwarding RuleSub-technique

Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset.[1][2]

EnterpriseT1585.001Social Media AccountsSub-technique

Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance.[1][2]

EnterpriseT1078Valid Accounts

Star Blizzard has used stolen credentials to sign into victim email accounts.[1][2]

EnterpriseT1586.002Email AccountsSub-technique

Star Blizzard has used compromised email accounts to conduct spearphishing against contacts of the original victim.[2]

EnterpriseT1059.007JavaScriptSub-technique

Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.[3]

EnterpriseT1593Search Open Websites/Domains

Star Blizzard has used open-source research to identify information about victims to use in targeting.[1][2]

Associated objects

Groups, software, and campaigns

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
05ac3aa0f07c7721...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle05ac3aa0f07c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  2. [2]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  3. [3]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  4. [4]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  5. [5]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  6. [6]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  7. [7]
    COLDRIVER

    (Citation: Google TAG COLDRIVER January 2024)

  8. [8]
    COLDRIVER

    (Citation: Google TAG COLDRIVER January 2024)

  9. [9]
    COLDRIVER

    (Citation: Google TAG COLDRIVER January 2024)

  10. [10]
    Callisto Group

    (Citation: CISA Star Blizzard Advisory December 2023)

  11. [11]
    Callisto Group

    (Citation: CISA Star Blizzard Advisory December 2023)

  12. [12]
    Callisto Group

    (Citation: CISA Star Blizzard Advisory December 2023)

  13. [13]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  14. [14]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  15. [15]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  16. [16]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  17. [17]
    SEABORGIUM

    (Citation: Microsoft Star Blizzard August 2022)

  18. [18]
    SEABORGIUM

    (Citation: Microsoft Star Blizzard August 2022)

  19. [19]
    SEABORGIUM

    (Citation: Microsoft Star Blizzard August 2022)

  20. [20]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  21. [21]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  22. [22]
    TA446

    (Citation: CISA Star Blizzard Advisory December 2023)

  23. [23]
    TA446

    (Citation: CISA Star Blizzard Advisory December 2023)

  24. [24]
    TA446

    (Citation: CISA Star Blizzard Advisory December 2023)

  25. [25]
    mitre-attackG1033
    Open source URL
  26. [26]
    mitre-attackG1033
    Open source URL
  27. [27]
    mitre-attackG1033
    Open source URL
  28. [28]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  29. [29]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  30. [30]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  31. [31]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  32. [32]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  33. [33]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  34. [34]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  35. [35]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  36. [36]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  37. [37]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  38. [38]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  39. [39]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  40. [40]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  41. [41]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  42. [42]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  43. [43]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  44. [44]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  45. [45]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  46. [46]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  47. [47]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  48. [48]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  49. [49]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  50. [50]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  51. [51]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  52. [52]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  53. [53]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  54. [54]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  55. [55]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  56. [56]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  57. [57]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  58. [58]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  59. [59]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  60. [60]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  61. [61]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  62. [62]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  63. [63]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  64. [64]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  65. [65]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  66. [66]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  67. [67]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  68. [68]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  69. [69]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  70. [70]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  71. [71]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  72. [72]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  73. [73]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  74. [74]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  75. [75]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  76. [76]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  77. [77]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  78. [78]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  79. [79]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  80. [80]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  81. [81]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  82. [82]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  83. [83]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  84. [84]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  85. [85]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  86. [86]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  87. [87]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  88. [88]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  89. [89]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
  90. [90]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  91. [91]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  92. [92]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  93. [93]
    Microsoft Star Blizzard August 2022

    Microsoft Threat Intelligence. (2022, August 15). Disrupting SEABORGIUM’s ongoing phishing operations. Retrieved June 13, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.