Star Blizzard
Star Blizzard is a Russia-linked cyber espionage threat actor also tracked as COLDRIVER, Callisto, Callisto Group, SEABORGIUM, TA446, UNC4057, BlueCharlie, Blue Callisto, Calisto, Cold River, Gossamer Bear, and related variants. Multiple governments and public reporting cited in the content attribute the group to the Russian Federal Security Service (FSB), including as a subordinate or operational unit within FSB Centre 18 / Center 18. The actor conducts tailored spear-phishing and credential theft operations against high-value targets. Reported targets include Russian and Belarusian civil society, Russian opposition figures in exile, independent media, international NGOs active in Eastern Europe, journalists, think tanks, academics, former officials, former intelligence and military officers, government and military personnel, defense contractors, Department of Energy staff, and at least one former U.S. ambassador. Reporting also states the group has targeted parliamentarians, universities, the public sector, and NGOs, and has focused heavily on NATO countries while also targeting Ukraine-related organizations. Observed tradecraft includes registering impersonation email accounts to spoof experts, colleagues, funders, government personnel, or organizations affiliated with the intended target; using compromised or lookalike accounts; and sending highly personalized phishing emails aligned to the victim’s professional context. In the documented "River of Phish" activity, the group used fake protected or encrypted PDF lures, sometimes omitting the attachment in an initial email to induce a reply before sending the lure. The PDFs directed victims to attacker-controlled infrastructure that fingerprinted the victim’s browser and system, optionally presented hCaptcha, and redirected to phishing pages impersonating Gmail or ProtonMail. The objective was credential theft, including passwords, 2FA codes, and session cookies, enabling account takeover. The content also states the group incorporated the Evilginx framework into spear-phishing activity and used JavaScript to redirect victims from adversary-controlled servers to Evilginx-hosted phishing infrastructure. Additional reporting in the content states Star Blizzard has uploaded malicious payloads to cloud storage sites and has sent emails with malicious PDF files to deliver malware. Google TAG reporting referenced in the content notes Microsoft uncovered a similar QR-code campaign tied to Callisto Group / Coldriver / Star Blizzard that targeted WhatsApp accounts linked to dozens of civil society organizations and journalists. The group has also been linked to hack-and-leak activity. The content states information stolen by COLDRIVER was used in hack-and-leak operations, including leaks related to UK-US trade documents ahead of the 2019 UK election and material used in 2022 to exacerbate Brexit-related political divisions in the United Kingdom. Law-enforcement and sanctions actions described in the content include U.S. and UK sanctions against Ruslan Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets as members or associates of the group, and U.S. Department of Justice and Microsoft actions to seize more than 100 domains allegedly used in the group’s spear-phishing infrastructure.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Non-Governmental Organizations
- Academia & Research
- Independent Media
- Military
Where they target
Geographies tied to known operations.
- 🇷🇺 Russia
- 🇺🇸 United States
- 🇺🇦 Ukraine
- 🇧🇾 Belarus
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
Associated vulnerabilities
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
2 more CVEs tied to this actor tracked in Mallory.
Observables
190 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing campaign targeting Russian opposition figures abroad, with targets apparently overlapping with contacts extracted from an activist’s seized phone.
Conducting phishing operations against opposition-linked individuals; mentioned here as later targeting people whose names were extracted from the seized phone.
Conducted phishing campaigns targeting individuals connected to Russian opposition and civil society activity.
Conducted a global hacking campaign and targeted individuals connected to Russian opposition and civil society, including Anastasiya Burakova and suspected targeting of Maxim Dbar.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.