RussiaWidely attributedUnknownMITRE G1033

Star Blizzard

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
1.6
Low signal strength
Mentions2
Sources1
High conf.2
Last seenMay 2026
First observed
2024-06-14
Last active
Origin
Russia
Aliases
5
Techniques
20
Campaigns
0
Russia

Attribution signals

2 mentions · 1 source
#1usehigh
Unspecified
eset
May 2026

"Russia-based SEABORGIUM and Iran-aligned TA453 groups use OSINT for reconnaissance ahead of spearphishing attacks on pre-selected targets."

#2reported onhigh
Victimology
ncsc-uk-all
May 2026

"The NCSC has previously reported on the targeting of government officials' accounts by China state-affiliated APT31, Russian Federal Security Service (FSB) actor Star Blizzard and Iran's Islamic Revolutionary Guard Corps (IRGC)."

Hedge terms observed

reported onuse