Star Blizzard is a Russia-based cyber-espionage and influence threat actor widely tracked under the aliases COLDRIVER, SEABORGIUM, Callisto Group, TA446, TAG-53, BlueCharlie, Blue Callisto, Calisto, Gossamer Bear, and UNC4057. Multiple government attributions assess the group is subordinate to the Russian Federal Security Service (FSB), specifically Centre 18. The actor has been active since at least 2017, with sustained operations documented from 2019 onward. Star Blizzard is primarily a spear-phishing and credential-harvesting operation focused on intelligence collection. It has heavily targeted individuals and organizations connected to government, defense, academia, think tanks, NGOs, political activity, journalism, and civil society, especially those involved in Russian affairs, Ukraine, Belarus, and broader NATO policy. The United Kingdom and United States have been among the most affected targets, with additional activity against other NATO countries, Eastern Europe, the Baltics, the Nordics, the Caucasus, and Ukraine. Public reporting also links the actor to targeting Russian opposition figures, independent media, and related communities abroad. The group’s tradecraft centers on detailed reconnaissance of victims’ professional and social relationships using open sources, social media, and professional networking platforms. Operators commonly impersonate trusted contacts, respected experts, colleagues, funders, or officials through fraudulent email and social media personas, then build rapport over time before delivering phishing lures. Common lures include invitations, policy or media discussions, grant or event themes, and fake protected-document workflows. Star Blizzard has frequently targeted personal email accounts to evade enterprise defenses. A defining feature of Star Blizzard operations is adversary-in-the-middle credential theft using EvilGinx or similar infrastructure. The actor harvests usernames, passwords, multi-factor authentication material, and web session cookies, enabling session hijacking and bypass of MFA protections. After account compromise, the group accesses victim mailboxes, steals emails and attachments, creates forwarding rules for persistence and collection, extracts contact and mailing-list data, and uses compromised accounts for follow-on phishing against additional victims. Star Blizzard has also been associated with hack-and-leak activity and politically relevant information operations. UK authorities publicly attributed a long-running campaign against British democratic institutions and politicians’ personal email accounts to FSB Centre 18 officers linked to this cluster. Reporting also describes the actor using allegedly stolen material to sow distrust and selectively leaking information for political effect. Recent reporting shows the actor continuing to adapt its infrastructure and phishing methods in response to public exposure, including changes to domain patterns and lure presentation. Separate but related reporting has tied similar Russian messaging-app phishing activity against high-value users to Star Blizzard-linked clusters, though not every such campaign has been publicly attributed to Star Blizzard specifically. Named individuals publicly linked by U.S. and UK authorities to Star Blizzard activity include Ruslan Peretyatko and Andrey Korinets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
2 more CVEs tied to this actor tracked in Mallory.
230 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of several actors in broader conflict-related reporting.
Conducts credential theft, intelligence collection, political targeting, and influence support against political figures, civil society, journalists, academia, and democratic organizations.
Named as a Centre 16 subunit involved in interference with UK politics and democratic processes.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.