Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: SEABORGIUM, Callisto Group, TA446, COLDRIVER
20
techniques
1
software
9,518
corpus matches
profile
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.
techniques
20 attributed · most-instrumented first
software
1 malware & tools attributed
Spica
S1140
read this carefully
9,518 corpus matches is not attribution
That count is indicators which exhibit techniques Star Blizzard is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
resource-development
+8 more techniques
showing 30 of 9,518
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.