Star Blizzard
Also reported as TA446, SEABORGIUM, Callisto Group, COLDRIVER, BlueCharlie and 39 other names. Sources disagree on the origin.
Reports per quarter
Techniques seen in the last two years
- T1566.001 3 reports in ATT&CK
- T1027.006 2 reports reports only
- T1059.007 2 reports in ATT&CK
- T1204.002 2 reports in ATT&CK
- T1566.002 2 reports reports only
- T1583.001 2 reports in ATT&CK
- T1027.002 1 report reports only
- T1027.010 1 report reports only
- T1027.012 1 report reports only
- T1027.013 1 report reports only
Show all 38 techniques Show fewer
- T1036 1 report reports only
- T1041 1 report reports only
- T1055.002 1 report reports only
- T1059.001 1 report reports only
- T1059.005 1 report reports only
- T1071.001 1 report reports only
- T1078 1 report in ATT&CK
- T1105 1 report reports only
- T1114.002 1 report in ATT&CK
- T1114.003 1 report in ATT&CK
- T1204.001 1 report reports only
- T1539 1 report in ATT&CK
- T1547.001 1 report reports only
- T1550.004 1 report in ATT&CK
- T1568.001 1 report reports only
- T1571 1 report reports only
- T1583.003 1 report reports only
- T1583.004 1 report reports only
- T1584.001 1 report reports only
- T1585.001 1 report in ATT&CK
- T1585.002 1 report in ATT&CK
- T1586.002 1 report in ATT&CK
- T1589 1 report in ATT&CK
- T1591 1 report reports only
- T1591.002 1 report reports only
- T1593 1 report in ATT&CK
- T1608.001 1 report in ATT&CK
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2009-1151 KEV
- CVE-2011-1255
- CVE-2012-0158 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-3893 KEV
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6332 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
Show all 87 CVEs Show fewer
- CVE-2014-7187
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-8651 KEV
- CVE-2016-0147
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-12617 KEV
- CVE-2017-3881 KEV
- CVE-2017-6736 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-5407
- CVE-2018-7600 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12641 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-27937
- CVE-2020-35730 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-9771
- CVE-2020-9934 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-40444 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1471
- CVE-2022-26134 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-40507
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-41352 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-22522
- CVE-2023-22523
- CVE-2023-23397 KEV
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-40077
- CVE-2023-40088
- CVE-2023-42793 KEV ransomware
- CVE-2023-45866
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-21413 KEV
- CVE-2025-0411 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Return of the mac(OS): Transparency, Consent, and Control (TCC) Database Manipulation - Interpres Security
-
Gamaredon Group - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Gamaredon Group - Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 117 reports Show fewer
-
Cold River - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cold River - Threat Group Cards: A Threat Actor Encyclopedia
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Microsoft Security Compliance and Identity
The original link failed its last check. Original publisher Detailsfor Microsoft Security Compliance and Identity
-
New APT34 Malware Targets The Middle East
The original link failed its last check. Original publisher Detailsfor New APT34 Malware Targets The Middle East
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine
-
Russian hackers targeted petroleum refining company in NATO state
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers targeted petroleum refining company in NATO state
-
Russian Threat Actor Impersonates Aerospace and Defense Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Threat Actor Impersonates Aerospace and Defense Companies
-
Blue Callisto orbits around US Laboratories in 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Blue Callisto orbits around US Laboratories in 2022
-
Exposing TAG-53’s Credential Harvesting Infrastructure Used for Russia-Aligned Espionage Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exposing TAG-53’s Credential Harvesting Infrastructure Used for Russia-Aligned Espionage Operations
-
Calisto show interests into entities involved in Ukraine war support
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Calisto show interests into entities involved in Ukraine war support
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Message from Recorded Future
-
Preparing for a Russian cyber offensive against Ukraine this winter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Preparing for a Russian cyber offensive against Ukraine this winter
-
Disrupting SEABORGIUM’s ongoing phishing operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Disrupting SEABORGIUM’s ongoing phishing operations
-
Continued cyber activity in Eastern Europe observed by TAG
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Continued cyber activity in Eastern Europe observed by TAG
-
Shortcut-Based (LNK) Attacks Delivering Malicious Code On The Rise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shortcut-Based (LNK) Attacks Delivering Malicious Code On The Rise
-
Update on cyber activity in Eastern Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Update on cyber activity in Eastern Europe
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
Tracking cyber activity in Eastern Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking cyber activity in Eastern Europe
-
Anticipating Cyber Threats as the Ukraine Crisis Escalates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anticipating Cyber Threats as the Ukraine Crisis Escalates
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Technical report Armagedon
-
Karkoff 2020 a new APT34 espionage operation involves Lebanon Government
The original link failed its last check. Detailsfor Karkoff 2020 a new APT34 espionage operation involves Lebanon Government
-
Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
-
2019 Cyber Threatscape Report I Accenture
The original link failed its last check. Original publisher Detailsfor 2019 Cyber Threatscape Report I Accenture
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The original link failed its last check. Detailsfor APT34 webmask project
-
From Hacking Team to hacked team to...-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Hacking Team to hacked team to...-
-
Threat Actor “Cold River”- Network Traffic Analysis and a Deep Dive on Agent Drable
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actor “Cold River”- Network Traffic Analysis and a Deep Dive on Agent Drable
-
DNSpionage Campaign Targets Middle East
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DNSpionage Campaign Targets Middle East
-
New traces of Hacking Team in the wild
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New traces of Hacking Team in the wild
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor new-traces-hacking-team-wild
-
Callisto Group | F-Secure Labs Malware Analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Callisto Group | F-Secure Labs Malware Analysis
-
SectorC08- Multi-Layered SFX in Recent Campaigns Target Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SectorC08- Multi-Layered SFX in Recent Campaigns Target Ukraine
Newest first. Details opens the report in Explore.