Star Blizzard

APT / StateG1033 ↗
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)20
SourceMITRE ATT&CK
0
Also known as:Blue CallistoBlueCharlieCOLD RELICCOLDRIVERCallisto GroupGOSSAMER BEARIRON FRONTIERSEABORGIUMTA446TAG-53UNC4057

About the group

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity31
Impact: High
T1566.001T1059.007T1539T1550.004ENTRYInitial accessSpearphishingAttachmentEXECExecutionJavaScriptCREDCredential accessSteal Web SessionCookieLATLateral movementWeb Session CookieCOLLCollectionRemote EmailCollection

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Star Blizzard uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →