AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Star Blizzard
Aliases: SEABORGIUM, Callisto Group, TA446, COLDRIVER
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.
Open interactive actor investigation
ATT&CK techniques
DomainsT1114.002
Remote Email CollectionT1550.004
Web Session CookieT1204.002
Malicious FileT1608.001
Upload MalwareT1539
Steal Web Session CookieT1589
Gather Victim Identity InformationT1585.002
Email AccountsT1566.001
Spearphishing AttachmentT1598.002
Spearphishing AttachmentT1598.003
Spearphishing LinkT1588.002
ToolT1583
Acquire InfrastructureT1114.003
Email Forwarding RuleT1585.001
Social Media AccountsT1078
Valid AccountsT1586.002
Email AccountsT1059.007
JavaScriptT1593
Search Open Websites/Domains
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Vulnerability Research & Exploit Development · explicit-nameModule 1 — Foundations: What CTI Is
Cyber Threat Intelligence (CTI) · explicit-nameModule 4 — Collection Sources
Cyber Threat Intelligence (CTI) · explicit-nameModule 5 — Analysis Techniques Tradecraft
Cyber Threat Intelligence (CTI) · explicit-nameModule 7 — Intelligence Products Sharing
Cyber Threat Intelligence (CTI) · explicit-nameModule 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · explicit-nameModule 2 — Reconnaissance and attack-surface mapping
Red Team & Offensive Security · explicit-nameModule 6 — Active Directory and identity attack paths
Red Team & Offensive Security · explicit-nameModule 13 — Red-team infrastructure and operations
Red Team & Offensive Security · explicit-nameNetwork behavior, protocols, and configuration recovery
Malware Analysis & Reverse Engineering · explicit-nameShared responsibility, governance, and service ownership
Cloud Security · explicit-namePosture management, exposure, vulnerabilities, attack paths, and validation
Cloud Security · explicit-name