Star Blizzard
Star Blizzard is a Russia-linked, state-sponsored cyber espionage threat actor tracked by Microsoft as Star Blizzard and also referred to in the provided content as Callisto, Callisto Group, COLDRIVER/Coldriver, SEABORGIUM, Gossamer Bear, BlueCharlie, ReUse Team, Dancing Salome, TA446, and UNC4057. The content states that the group is an operational unit within Center 18 of the Russian Federal Security Service (FSB), and UK authorities assess it is almost certainly subordinate to the FSB. The group is known for highly tailored spear-phishing and credential-phishing operations conducted since at least 2016. Reported targets include governments, militaries, private-sector organizations, media, civil society organizations, journalists, think tanks, NGOs, parliamentarians, universities, public-sector entities, defense contractors, former intelligence personnel, Department of Defense and Department of State personnel, Department of Energy staff, and a Ukraine-based defense contractor. The content also states that the group targeted webmail accounts and sought persistent access to steal or exfiltrate sensitive information, including information related to defense, foreign affairs, and nuclear energy research. UK reporting in the content links the group to interference in British politics and democratic processes, including access to UK-US trade documents made public before the 2019 UK election and the 2018 hack of the Institute for Statecraft. Tradecraft described in the content centers on spear-phishing, impersonation, credential theft, and malware delivery. The group used spoofed and seemingly legitimate email accounts impersonating trusted contacts or government personnel, malicious domains and shortened URLs, and phishing infrastructure designed to harvest credentials. The content states that Star Blizzard used JavaScript to redirect victim traffic from adversary-controlled servers to servers hosting the Evilginx phishing framework, and that it incorporated the open-source EvilGinx framework into spear-phishing activity. It also states that the group sent emails with malicious PDF attachments and lured targets into opening malicious PDF files to deliver malware. Additional reporting in the content ties the actor to QR-code phishing targeting WhatsApp accounts of civil society organizations and journalists. The content also describes law-enforcement and industry disruption actions against the group’s infrastructure. Microsoft and the U.S. Department of Justice seized more than 100 domains allegedly used in Star Blizzard/Callisto spear-phishing and credential-theft operations, including 66 domains through Microsoft civil action and 41 domains through a U.S. seizure warrant. Microsoft reported that the actor targeted at least 82 customers since January 2023 and more than 30 civil society organizations between January 2023 and August 2024. Named individuals tied to the group in the content are Ruslan Aleksandrovich Peretyatko, identified as an FSB officer, and Andrey Stanislavovich Korinets, identified as an IT worker in Syktyvkar, Russia and also referred to by UK authorities as Alexei Doguzhev. The U.S. and UK sanctioned both individuals, and U.S. authorities charged them in connection with spear-phishing and hacking conspiracies attributed to the group.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Commercial & Professional Services
- Government & Administration
- Non-Governmental Organizations
- Academia & Research
- Military
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇬🇧 United Kingdom
- 🇺🇦 Ukraine
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
Associated vulnerabilities
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
The exploit chains six CVEs: CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
2 more CVEs tied to this actor tracked in Mallory.
Observables
171 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a similar QR-code-based campaign targeting WhatsApp accounts associated with civil society organizations and journalists.
Named threat actor referenced in reporting on the Ukraine conflict and Eastern Europe cyber activity.
Listed as a threat actor associated with Azure Active Directory account takeover, persistence, privilege escalation, and related cloud-focused post-compromise activity detected via PowerShell module installation.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.