Skip to content
RussiaState-SponsoredActiveMITRE G1033Malpedia ↗

Star Blizzard

FSB Centre 18 credential phishing against academics, journalists, NGOs, and former intelligence officials — with hack-and-leak as the follow-through.

ATTRIBUTED TORussia › FSB — Federal Security Service › Centre 18

Open MITRE Navigator layer ↗Download profile JSON
Active
2015–present
Motivation
Espionage, Information Operations
Aliases
10
Exploited CVEs
0
ATT&CK techniques
9
Cited sources
7

Overview

Star Blizzard runs one of the most persistent credential-phishing operations attributed to any state service, and it is notable less for technical capability than for the care put into social engineering.

Operators build rapport before ever sending a malicious link. They impersonate known colleagues of the target, open with an innocuous message referencing a genuine shared interest or upcoming conference, exchange several benign emails, and only then send a document link leading to an Evilginx-style adversary-in-the-middle proxy that captures both credentials and the session cookie — defeating most MFA implementations.

The targeting is politically specific: academics researching Russia, journalists covering the war, NGOs and human rights organisations, defence policy think tanks, and — repeatedly — former senior intelligence and diplomatic officials. Several operations have culminated in hack-and-leak: in 2022 the mailbox of a former MI6 chief was compromised and material published through a fabricated leak site.

In December 2023 the UK sanctioned and the U.S. indicted two individuals, naming Ruslan Peretyatko as an officer of FSB Centre 18. Microsoft and the U.S. Department of Justice seized 107 domains in a joint civil action in October 2024, though the group re-established infrastructure within months.

Attribution

Down to the named unit where public evidence supports it.

RussiaFSB — Federal Security ServiceCentre 18Confirmed

Centre for Information Security, FSB

The UK Foreign, Commonwealth and Development Office sanctioned two individuals in December 2023, identifying Ruslan Aleksandrovich Peretyatko as an officer of FSB Centre 18 and Andrey Stanislavovich Korinets as a co-participant. The U.S. Department of Justice unsealed a parallel indictment the same day. Microsoft and the DOJ subsequently seized over one hundred domains used by the group in an October 2024 civil action.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 7 organisations.

MITRE ATT&CK

index ↗
  • Star Blizzard

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Star BlizzardFormerly SEABORGIUM
  • SEABORGIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Gossamer Bear

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • UNC4057
  • COLDRIVERGoogle Threat Intelligence designator

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Recorded Future Insikt Group

index ↗
  • BlueCharlie
  • TAG-53Earlier provisional designator

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Proofpoint

index ↗
  • TA446

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • Callisto Group

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United KingdomUnited StatesUkraineGermanyPolandBaltic states

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

SPICAbackdoor

Rust backdoor delivered via a decoy PDF that appears encrypted; the group's first confirmed custom malware, disclosed by Google TAG in 2024.

Malpedia ↗
LOSTKEYSmalware

File-stealer delivered through a fake CAPTCHA 'ClickFix' lure that persuades the target to paste a PowerShell command themselves.

HYPERSCRAPEutility

Mailbox scraping tool that authenticates with a stolen session, downloads mail, and reverts read-status flags to hide the theft.

Shared, commodity & living-off-the-land

Evilginxframework

Open-source adversary-in-the-middle phishing proxy that captures session cookies alongside credentials, defeating most MFA.

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 9 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
9 techniques across 6 tactics · 6 with actor-specific notes

Reconnaissance

1

Resource Development

2

Execution

1

Credential Access

2

Campaign timeline

  1. UK Hack-and-Leak Operations

    Credential phishing against former senior officials, culminating in the compromise of a former MI6 chief's mailbox and publication of the material through a fabricated leak site. Preceded by weeks of benign rapport-building correspondence in each case.

    GovernmentThink Tanks & AcademiaNGO & Civil SocietyMedia & Journalism

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.