The UK government publicly attributed a long-running cyber campaign against democratic institutions and politicians’ personal email accounts to officers of Centre 18 of Russia’s FSB, identifying the activity under names including COLDRIVER, Star Blizzard, SEABORGIUM, Callisto, and BlueCharlie. Officials said the operation had run since at least 2015, included the compromise of then trade minister Liam Fox’s email in 2019, and involved the selective leaking of stolen material later cited during a UK election campaign. In response, London summoned the Russian ambassador and sanctioned Ruslan Peretyatko and Andrew Korinets following a National Crime Agency investigation.
Security researchers said the group has continued refining its credential-harvesting tradecraft to evade detection, replacing exposed infrastructure with dozens of new domains and using legitimate cloud services such as Google Docs and Microsoft OneDrive as phishing lures. Prior reporting linked the actor to Evilginx-based phishing kits designed to steal credentials and MFA tokens, with targets spanning governments, defense organizations, think tanks, NGOs, journalists, and academic institutions across Europe and North America. Microsoft warned that the actor’s ongoing attacks show increased sophistication and evasion, underscoring that the campaign remains active despite public exposure and sanctions.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
A joint advisory from the UK, US, Australia, Canada, and New Zealand said Star Blizzard continued spear-phishing through 2023 and described its use of EvilGinx to steal credentials and session cookies, bypass MFA, and set mail-forwarding rules in compromised email accounts. The advisory also said the actor had targeted academia, defense, government, NGOs, think tanks, and politicians since 2019, with activity expanding during 2022 to defense-industrial targets and US Department of Energy facilities.
Microsoft published a blog post warning that Star Blizzard continues to refine its tradecraft to evade detection and increase sophistication in ongoing attacks. The post was cited alongside the UK attribution announcement.
The United Kingdom added Ruslan Peretyatko and Andrew Korinets to its Cyber Sanctions list in connection with the campaign. The National Crime Agency said the sanctions followed a lengthy and complex investigation.
The British government publicly attributed the long-running campaign against UK democratic institutions and personal email accounts to officers of Centre 18 of Russia’s FSB. Officials said the Russian ambassador was summoned and described the operation as sustained but unsuccessful.
Microsoft announced it had disrupted ongoing SEABORGIUM phishing operations and published details about the actor’s credential-theft activity. The action marked a separate vendor-led disruption effort against infrastructure used by the group.
Google TAG said COLDRIVER continued credential-phishing against government, defense, NGO, and media targets using links in emails and cloud-hosted lure documents. TAG also said Google Safe Browsing blocked COLDRIVER phishing domains and published indicators tied to the campaign.
A website called “Very English Coop d’Etat” appeared and purported to reveal a Brexit-related plot. Google TAG later told Reuters it had technically linked the site to CALISTO operations, while Sekoia.io said similarities to earlier hack-and-leak campaigns were weak.
Google TAG published indicators of compromise and linked CALISTO/COLDRIVER to spear-phishing campaigns against Western NGOs, think tanks, and defense-sector targets. The reporting described the actor’s use of freshly created Gmail accounts and cloud-hosted lure documents to route victims to phishing domains.
The UK said the FSB-linked group targeted then trade minister Liam Fox’s email account in 2019. Stolen material was selectively leaked and later cited by Jeremy Corbyn during the UK election campaign.
ANSSI reported a large spearphishing and phishing campaign targeting government, diplomatic, think tank, and other strategic organizations, with traces dating back to 2017. The report documented malicious infrastructure and noted open-source technical links to activity associated with Kimsuky and Group123, without making a formal attribution.
The UK said a sustained cyber campaign targeting the personal email accounts of hundreds of people in Britain, including politicians from multiple parties, has been active since 2015. The activity was later linked by the UK to officers of FSB Centre 18 and the group tracked as Callisto/COLDRIVER/Star Blizzard/SEABORGIUM.
Recorded Future’s Insikt Group reported that TAG-53 was conducting phishing and likely credential-harvesting operations and assessed overlaps with Callisto Group, COLDRIVER, and SEABORGIUM. Researchers identified infrastructure impersonating organizations including Global Ordnance, UMO Poland, the Commission for International Justice and Accountability, Blue Sky Network, DTGruelle, and Russia’s Ministry of Internal Affairs, and observed a spoofed Microsoft login page on drive-globalordnance[.]com.
Recorded Future reported that BlueCharlie, also known as Calisto/COLDRIVER/SEABORGIUM/StarBlizzard, replaced previously exposed infrastructure with 94 new domains for credential harvesting and follow-on espionage. Researchers assessed the change was likely a response to public exposure of the group’s earlier tactics and infrastructure.
Sekoia.io published analysis of CALISTO’s credential-harvesting infrastructure, identifying 24 Evilginx-enabled domains with medium to high confidence and a likely low-confidence phishing domain targeting the Ukrainian Ministry of Defense. The report also described operator OPSEC mistakes, including default redirects to a Rickroll video and The New York Times homepage, that helped uncover additional servers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 73 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcesocradar.io
Open sourcencsc.gov.uk
Open sourcetherecord.media
Open sourceblog.google
Open sourceblog.sekoia.io
Open sourcecert.ssi.gouv.fr
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.