Reconnaissance
1 technique·derived
Multi-message benign rapport-building before any malicious link.
FSB Centre 18 credential phishing against academics, journalists, NGOs, and former intelligence officials — with hack-and-leak as the follow-through.
ATTRIBUTED TORussia › FSB — Federal Security Service › Centre 18
Star Blizzard runs one of the most persistent credential-phishing operations attributed to any state service, and it is notable less for technical capability than for the care put into social engineering.
Operators build rapport before ever sending a malicious link. They impersonate known colleagues of the target, open with an innocuous message referencing a genuine shared interest or upcoming conference, exchange several benign emails, and only then send a document link leading to an Evilginx-style adversary-in-the-middle proxy that captures both credentials and the session cookie — defeating most MFA implementations.
The targeting is politically specific: academics researching Russia, journalists covering the war, NGOs and human rights organisations, defence policy think tanks, and — repeatedly — former senior intelligence and diplomatic officials. Several operations have culminated in hack-and-leak: in 2022 the mailbox of a former MI6 chief was compromised and material published through a fabricated leak site.
In December 2023 the UK sanctioned and the U.S. indicted two individuals, naming Ruslan Peretyatko as an officer of FSB Centre 18. Microsoft and the U.S. Department of Justice seized 107 domains in a joint civil action in October 2024, though the group re-established infrastructure within months.
Down to the named unit where public evidence supports it.
Centre for Information Security, FSB
The UK Foreign, Commonwealth and Development Office sanctioned two individuals in December 2023, identifying Ruslan Aleksandrovich Peretyatko as an officer of FSB Centre 18 and Andrey Stanislavovich Korinets as a co-participant. The U.S. Department of Justice unsealed a parallel indictment the same day. Microsoft and the DOJ subsequently seized over one hundred domains used by the group in an October 2024 civil action.
Attributing sources
10 designators across 7 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Rust backdoor delivered via a decoy PDF that appears encrypted; the group's first confirmed custom malware, disclosed by Google TAG in 2024.
Malpedia ↗File-stealer delivered through a fake CAPTCHA 'ClickFix' lure that persuades the target to paste a PowerShell command themselves.
Mailbox scraping tool that authenticates with a stolen session, downloads mail, and reverts read-status flags to hide the theft.
Shared, commodity & living-off-the-land
Open-source adversary-in-the-middle phishing proxy that captures session cookies alongside credentials, defeating most MFA.
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Multi-message benign rapport-building before any malicious link.
2 techniques·derived
Personas impersonating known colleagues of the target.
1 technique·derived
Spearphishing Link.
1 technique·derived
ClickFix fake-CAPTCHA lure delivering LOSTKEYS.
2 techniques·derived
Evilginx proxy capturing session cookies. Primary MFA bypass mechanism.
2 techniques·derived
Persistent mailbox rules surviving password reset.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Multi-message benign rapport-building before any malicious link
Personas impersonating known colleagues of the target
ClickFix fake-CAPTCHA lure delivering LOSTKEYS
Evilginx proxy capturing session cookies
Primary MFA bypass mechanism
Persistent mailbox rules surviving password reset
Credential phishing against former senior officials, culminating in the compromise of a former MI6 chief's mailbox and publication of the material through a fabricated leak site. Preceded by weeks of benign rapport-building correspondence in each case.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Curated links to the reports that established what is known about this group.