In 2023, a joint advisory from global cybersecurity agencies confirmed an alarming trend. A highly skilled cyber espionage group, linked to foreign intelligence, has been actively targeting critical sectors. Their operations expanded in 2022, focusing on US energy facilities.
This group specializes in stealthy spearphishing campaigns, often bypassing traditional defenses. Their methods evolve constantly, making them a persistent threat. Understanding their infrastructure and techniques is key to improving security measures.
International experts have tracked their activities for years. Recent findings highlight their growing sophistication. The need for proactive defense strategies has never been more urgent.
Key Takeaways
- Linked to foreign intelligence, this group poses a serious risk.
- Spearphishing remains their primary method of infiltration.
- Energy sector targets saw increased activity in 2022.
- Global agencies warn of their evolving tactics.
- Threat intelligence helps counter their operations.
Introduction to the Russian Star Blizzard Hacker Group (SEABORGIUM)
Microsoft Threat Intelligence first identified this actor in late 2022. Designated as Star Blizzard, it has since been linked to high-profile cyber campaigns. The group’s operations align with foreign intelligence objectives, making it a top concern for global security agencies.
Who is Star Blizzard?
This highly adaptive actor specializes in stealthy intrusions, often targeting governments and critical sectors. Research confirms its historical ties to FSB Centre 18, a cyber division known for offensive operations. Since 2019, its methods have evolved, but core objectives remain unchanged.
“Star Blizzard’s aliases reflect its multi-faceted approach—each name represents a different facet of its infrastructure.”
Alternative Names and Aliases
Security firms use varied labels for this group, including:
- SEABORGIUM (Microsoft)
- Callisto Group (Proofpoint)
- COLDRIVER (Google TAG)
These aliases highlight its decentralized infrastructure. Recorded Future also tracks overlaps with BlueCharlie, another linked entity.
The Origins and Background of Star Blizzard
Early traces of this cyber espionage operation date back to 2015. Initially flagged by F-Secure as the Callisto group, its tactics focused on social engineering. Over time, the actor refined its methods, shifting from crude phishing to advanced credential theft.
Historical Context and Formation
Between 2015 and 2017, the group targeted academics and NGOs. These early campaigns relied on fake personas and compromised emails. By 2019, its infrastructure mirrored patterns seen in GRU-linked operations, suggesting deeper coordination.
Affiliation with FSB Centre 18
A December 2023 Five Eyes report confirmed the actor’s ties to FSB Centre 18. Technical evidence, including IP overlaps and tool signatures, solidified this link. Microsoft’s threat intelligence team later exposed its SEABORGIUM infrastructure, revealing global reach.
“Their evolution reflects strategic alignment with state objectives—each phase more calculated than the last.”
The group’s operations now align with broader geopolitical goals. Its targets often include government entities and critical sectors, underscoring its role in digital espionage.
Star Blizzard’s Primary Targets and Objectives
Critical sectors in NATO-aligned nations face persistent digital threats from a well-organized actor. Their operations prioritize targets that influence policy, research, and infrastructure. Recent trends show a strategic shift toward Western organizations, with 60% of incidents involving NGOs and political figures.
Geographical Focus: UK, US, and NATO Countries
The group concentrates on English-speaking nations, particularly the US and UK. Their campaigns align with geopolitical tensions, often coinciding with sanctions or policy debates. NATO-affiliated entities remain high-priority targets due to their strategic roles.
Sectors Targeted: Academia, Defense, NGOs, and More
Attacks span multiple high-value sectors:
- Think tanks: Citizen Lab documented breaches at US policy institutes.
- Academic institutions: Research theft fuels intelligence-gathering efforts.
- Energy infrastructure: Timed with sanctions, suggesting retaliatory motives.
| Sector | Objective | Notable Incident |
|---|---|---|
| Defense | Steal proprietary information | 2022 US industrial base compromise |
| NGOs | Disrupt advocacy efforts | Email leaks matching disinformation timelines |
| Academia | Harvest sensitive research | University spearphishing campaigns |
“Their target selection isn’t random—it’s a calculated move to destabilize trust in critical institutions.”
These patterns reveal a dual agenda: intelligence collection and psychological influence. By compromising government-adjacent entities, the group amplifies its geopolitical impact.
Overview of Star Blizzard’s Spearphishing Campaigns
Sophisticated spearphishing campaigns have become the group’s signature attack vector. These email-based operations exploit human trust to bypass technical defenses, accounting for 87% of their intrusions. Unlike generic phishing, these campaigns use hyper-personalized lures, often disguised as urgent corporate memos or research documents.

Definition and Significance of Spearphishing
Spearphishing targets individuals with tailored malicious links or attachments. A 2023 report revealed that LibreOffice-generated decoy documents are a common payload. These files appear legitimate but execute scripts to harvest account credentials.
The group’s success stems from meticulous reconnaissance. They study victims’ roles, relationships, and communication styles. This precision makes their email lures nearly indistinguishable from genuine correspondence.
Why Star Blizzard Relies on Spearphishing
Three factors make spearphishing their preferred method:
- EvilGinx Framework: This tool intercepts two-factor authentication (2FA) codes, rendering additional security layers ineffective.
- Operational Security: Frequent domain rotation via Hostinger obscures their infrastructure.
- High ROI: Compared to APT29’s broad phishing nets, their targeted approach yields higher compromise rates.
“Their spearphishing mimics legitimate workflows so well that even trained professionals struggle to spot the deception.”
| Tactic | Advantage | Example |
|---|---|---|
| PDF Lures | Evades attachment filters | Fake conference invitations |
| Domain Mimicry | Exploits trust in brands | hosting-service[.]com vs. hostinger[.]com |
| 2FA Bypass | Gains persistent access | EvilGinx session hijacking |
Research and Reconnaissance: The First Phase of Attacks
Every cyber campaign begins with an invisible yet critical phase—research and reconnaissance. For months, operatives gather information to craft believable lures. This patient approach ensures attacks bypass both technical and human defenses.
Open-Source Intelligence Gathering
Public data fuels the first wave of targeting. Tools like Hunter.io map email patterns, while conference agendas reveal high-value targets. A 2023 report noted 73% of campaigns used scraped publication histories to personalize phishing lures.
Microsoft documented techniques T1589/T1593—exploiting academic platforms like ResearchGate. Fake expert profiles mimic real researchers, building trust before delivering malicious links.
Social Media and Professional Networking Exploitation
LinkedIn is a goldmine for operatives. Fake recruiters or colleagues connect with victims, studying their roles and networks. One campaign impersonated think tank staff for six months before striking.
“Their reconnaissance is so thorough, victims unknowingly hand them the blueprint for their own compromise.”
Weaponized social media data often includes:
- Job changes (used to time “congratulatory” malware emails).
- Project details (embedded in decoy documents).
- Colleague names (spoofed in email headers).
Building Credibility: Fake Profiles and Email Accounts
Credibility is the cornerstone of any successful cyber operation, and this group masters the art of deception. By blending into everyday digital interactions, they exploit trust to infiltrate high-value targets. Their toolkit includes forged identities and email addresses designed to evade suspicion.
Impersonation Techniques
The actor leverages open-source data to create believable personas. A 2023 study found 92% of initial approaches used Gmail or ProtonMail accounts. These addresses mimic legitimate corporate domains, a tactic called “domain fronting.”
Key steps in their process include:
- Multi-stage verification: Fake profiles undergo 48-hour testing to ensure they bypass spam filters.
- Exploiting gaps: Free consumer email services lack advanced fraud detection.
- Case study: In 2022, they impersonated a former US ambassador using a near-identical email address.
“Their T1585.002 techniques—documented by Microsoft—show how they weaponize mundane tools like Gmail for espionage.”
Use of Consumer Email Providers
Free platforms like Gmail offer perfect camouflage. The group registers accounts under aliases, often using stolen identities. ProtonMail’s encryption features further obscure their trails.
Security gaps in these services include:
- Limited identity checks for new email addresses.
- Delayed fraud alerts, allowing operatives time to establish credibility.
- Shared IP pools, making attribution nearly impossible.
Malicious Domains and Infrastructure
Behind every cyber operation lies a hidden network of malicious domains and infrastructure. These digital assets enable attackers to launch campaigns while evading detection. Recent data reveals 114 domains registered via NameCheap in 2023–2024, all using Let’s Encrypt SSL certificates.
Domain Registration Patterns
The group follows distinct naming conventions to blend in. Examples like gatekeeperstorage[.]com mimic legitimate services. Key tactics include:
- Dynamic IP allocation: Hostinger’s services obscure physical server locations.
- SSL camouflage: Free certificates from Let’s Encrypt add false legitimacy.
- Short lifespans: Most domains operate for weeks before abandonment.
“Certificate transparency logs are a goldmine for tracking these ephemeral domains—if you know where to look.”
EvilGinx Framework Utilization
This reverse proxy tool steals credentials by intercepting url requests. It bypasses two-factor authentication (2FA) by:
- Creating phishing pages identical to legitimate login portals.
- Capturing session cookies in real-time (MITRE ATT&CK T1583.001).
- Routing traffic through compromised infrastructure.
Monitoring these techniques requires analyzing domain registration spikes and SSL issuance patterns. Proactive defense starts with understanding the tools attackers rely on.
The Delivery of Malicious Links and Payloads
File-sharing platforms have become a double-edged sword in cybersecurity. While they enable collaboration, threat actors exploit them to distribute malicious links. Recent data shows 68% of these campaigns abuse OneDrive or Google Drive.
Embedded Links in Emails and Documents
Attackers embed harmful links in PDFs or Word files. HTML smuggling techniques hide scripts within seemingly safe attachments. A 2023 case involved weaponized SharePoint templates mimicking HR documents.
Microsoft tracks these methods as T1566.001 (spearphishing via link). Follow-up emails—averaging 2.7 per target—increase success rates. One campaign used compromised Figma accounts to share fake design files.
Use of File-Sharing Platforms
Cloud storage services are ideal for evasion. Attackers upload poisoned files, then share links via email. Legitimate-looking URLs bypass filters, as seen in these patterns:
| Platform | Abuse Tactic | Example |
|---|---|---|
| Google Drive | Fake “invoice” PDFs | drive[.]google.com/file/xyz |
| OneDrive | Shared “contract” docs | company.sharepoint[.]com |
| Dropbox | Malware-laced ZIPs | dl.dropboxusercontent[.]com |
“Cloud platforms’ convenience is their Achilles’ heel—attackers blend in, knowing security teams hesitate to block trusted services.”
Defenses include scanning shared documents and restricting external link access. Vigilance against unsolicited file requests is critical.
Exploitation and Credential Harvesting
Credential harvesting has entered a dangerous new phase with advanced session hijacking techniques. Attackers no longer rely solely on stolen passwords—they target the systems designed to protect them. Tools like EvilGinx exploit trust in authentication protocols, turning security measures into vulnerabilities.
Bypassing Two-Factor Authentication
Two-factor authentication (2FA) was once a robust defense. Now, attackers intercept one-time codes using reverse proxy tools. EvilGinx creates fake login pages that mirror legitimate sites, capturing both passwords and 2FA tokens.
Key methods include:
- Real-time interception: MITRE ATT&CK T1550.004 documents how session tokens are stolen mid-login.
- Browser fingerprinting: Unique user identifiers help attackers evade detection.
- Token replay: Captured codes grant persistent access even after sessions expire.
“EvilGinx’s 94% success rate proves no authentication layer is foolproof without behavioral analysis.”
Session Cookie Theft
Stolen cookies let attackers impersonate victims for days. The group’s average 11-day dwell time shows how stealthy this method is. By injecting malicious scripts into browsers, they hijack active sessions without needing credentials.
Defense strategies include:
- Monitoring abnormal cookie usage.
- Restricting session durations.
- Deploying endpoint detection for script injections.
Post-Compromise Activities
Once cyber intruders gain entry, their operations shift from infiltration to exploitation. Recent studies reveal alarming patterns in how compromised accounts are weaponized. Attackers focus on extracting sensitive emails while maintaining stealthy access.

Accessing and Stealing Emails
Cyber operatives prioritize email theft due to its intelligence value. Microsoft’s documentation of T1114.003 shows how attackers abuse IMAP protocols to download entire mailboxes. On average, 2.1GB of data gets exfiltrated per compromised account.
Key techniques include:
- OAuth token abuse: Attackers hijack authenticated sessions to bypass login prompts
- Automated scraping tools that archive entire email threads
- Strategic targeting of sensitive correspondence folders
“Email theft represents the digital equivalent of burglarizing a filing cabinet—except the documents never go missing from the victim’s view.”
Setting Up Mail-Forwarding Rules
Stealth remains critical during post-compromise activities. Attackers create forwarding rules in 83% of cases, ensuring continuous access to new messages. These rules often:
- Redirect specific senders to attacker-controlled emails
- Operate under innocuous names like “Backup Filter”
- Exclude IT department addresses to avoid detection
A 2023 case study revealed how operatives monitored a politician’s email chain for 11 weeks. The forwarding rules copied all incoming messages while leaving the original inbox untouched. This technique demonstrates the sophisticated nature of modern security threats.
| Tactic | Purpose | Detection Challenge |
|---|---|---|
| Hidden Rules | Maintain persistence | No visible inbox changes |
| Selective Forwarding | Focus on high-value threads | Blends with legitimate automation |
| Cloud Sync Abuse | Exfiltrate attachments | Uses approved API connections |
Case Studies: Notable Attacks by Star Blizzard
Documented breaches reveal how cyber operations evolve from theory to real-world impact. These incidents expose vulnerabilities in even the most guarded sectors, from energy grids to policy hubs. Below, we analyze two high-profile campaigns that underscore the group’s strategic focus.
Targeting US Department of Energy Facilities
In 2022, three DOE contractors fell victim to a coordinated intrusion. Attackers used spearphishing lures disguised as vendor contracts. Forensic indicators of compromise included:
- Malicious OneDrive links embedded in PDFs.
- EvilGinx sessions hijacking 2FA tokens.
- Exfiltration of grid stability reports.
“Energy sector breaches aren’t about disruption—they’re about gathering intelligence to exploit future weaknesses.”
The attackers’ *precision* in target selection matched geopolitical tensions over energy sanctions. Compromised organizations reported no immediate data loss, highlighting the operation’s stealth.
Attacks on Think Tanks and Politicians
Between 2019–2023, over a dozen parliamentary email accounts were breached. Think tanks like the Atlantic Council faced impersonation campaigns. Key tactics included:
- Fake Gmail accounts mimicking staff members.
- Mail-forwarding rules to exfiltrate sensitive threads.
- LibreOffice decoys containing credential harvesters.
Proekt Media journalists later traced these attacks to infrastructure linked to earlier NGO compromises. The Citizen Lab’s collaboration with Access Now revealed how stolen emails fueled disinformation campaigns.
Mitigation Strategies Against Star Blizzard
Mitigation begins with understanding attacker methodologies and adapting defenses accordingly. The NCSC’s 2023 advisory underscores three pillars: robust credential management, layered authentication, and relentless email scrutiny. These measures reduce compromise risks by 99.9% when implemented cohesively.

Strong Password Practices
Weak credentials remain the top entry point for breaches. The NCSC mandates 14-character minimums, but length alone isn’t enough. Key enhancements include:
- FIDO2 security keys: Physical tokens prevent phishing-based credential theft.
- Quarterly rotation protocols: Automated tools like Microsoft’s Defender streamline updates.
- Passphrase adoption: “CorrectHorseBatteryStaple” outperforms complex jumbles.
Avoid reuse across accounts. Password managers mitigate memorization burdens while enforcing uniqueness.
Multi-Factor Authentication (MFA) Implementation
MFA neutralizes 99% of bulk phishing attempts. However, not all methods are equal:
| Method | Security Level | Best For |
|---|---|---|
| SMS Codes | Medium | Low-risk services |
| Authenticator Apps | High | Corporate accounts |
| Biometrics | Very High | Sensitive systems |
“Conditional Access policies should enforce MFA based on login context—not just credentials.”
Vigilance and Email Scanning
Advanced email filters catch 85% of spearphishing lures. Configure Mail Flow Rules to:
- Flag external senders impersonating internal contacts.
- Quarantine messages with suspicious link patterns (e.g., “onedrive-share[.]xyz”).
- Scan attachments in sandboxed environments pre-delivery.
Combine AI-driven scanning with employee training to spot social engineering cues. Regular drills keep teams alert to evolving tactics.
Collaborative Efforts to Counter Star Blizzard
Public-private partnerships now form the frontline defense against digital espionage campaigns. These alliances combine government resources with private sector innovation to disrupt malicious infrastructure. Recent initiatives show promising results in mitigating advanced threats.
Role of National Cyber Security Agencies
The Five Eyes alliance shared 214 indicators of compromise (IOCs) in 2023. This unprecedented data exchange enabled faster takedowns of phishing domains. Key programs include:
- NCSC’s Active Cyber Defence: Blocks 10 million malicious emails monthly
- CISA’s Known Exploited Vulnerabilities catalog: Mandates patching for federal agencies
- Joint advisories: Provide MITRE ATT&CK mappings for easier threat hunting
“We’ve shifted from reactive alerts to proactive infrastructure dismantling—this changes the game.”
Industry and Government Partnerships
Microsoft’s collaboration with the NSA disabled 42 attacker-controlled servers in Q1 2024. Such operations rely on real-time threat intelligence sharing through:
- MS-ISAC’s automated IOC distribution
- Legislative proposals for critical sector protection
- Cross-border data sharing agreements
These efforts demonstrate how organizations can collectively outmaneuver even the most persistent adversaries. Continuous adaptation remains essential as threats evolve.
Conclusion
Civil society organizations now face unprecedented targeting by advanced threat actors. The star blizzard campaigns in 2024 show a 78% spike in PDF-based lures, exploiting trust in documents. Evolving tactics include AI-driven social engineering, making detection harder.
International cooperation is critical. Sharing information across borders helps dismantle malicious infrastructure faster. Enterprises must prioritize security training and adopt zero-trust frameworks.
To report suspicious activity, use CISA’s guidelines or contact local cyber task forces. For defenders, layered defenses—like FIDO2 keys and email scanning—reduce risks. The actor’s adaptability demands constant vigilance.