Star Blizzard Persistent Spearphishing Campaign

Russian FSB Star Blizzard systematic spearphishing campaign targeting defence, government, think tanks, NGOs and journalists in UK, US and NATO countries. Credential harvesting via fake OneDrive and Microsoft login pages. NCSC and CISA joint advisory 2023.

Start date
1 January 2022
End date
Techniques
15

Attributed actors

Techniques (15)

collection1
T1114.002Remote Email Collection
command-and-control2
T1105Ingress Tool Transfer
T1071.001Web Protocols
credential-access1
T1539Steal Web Session Cookie
discovery2
T1082System Information Discovery
T1083File and Directory Discovery
execution1
T1059.001PowerShell
exfiltration1
T1041Exfiltration Over C2 Channel
initial-access3
T1566.002Spearphishing Link
T1078Valid Accounts
T1566.001Spearphishing Attachment
persistence2
T1078Valid Accounts
T1547.001Registry Run Keys / Startup Folder
privilege-escalation2
T1078Valid Accounts
T1547.001Registry Run Keys / Startup Folder
reconnaissance1
T1598.003Spearphishing Link
stealth3
T1078Valid Accounts
T1070.004File Deletion
T1027Obfuscated Files or Information

Indicators of compromise

No IOCs linked to this campaign yet.