Skip to content
Deep Dive high Governmentcivil-societydefencethink-tanksacademiamedia

Star Blizzard: The FSB's Spearphishing Arm Targeting Civil Society and Government

Executive Summary

Star Blizzard is one of Russia’s most patient and persistent cyber espionage operations. Formally linked to the FSB’s Centre 18 — the Federal Security Service’s internal information security unit — this threat actor has conducted targeted spearphishing campaigns against Western governments, politicians, journalists, academics, think tanks, and civil society organisations for over a decade. Unlike destructive Russian APTs such as Sandworm, Star Blizzard’s mandate is intelligence collection: compromising email accounts, exfiltrating documents, and monitoring communications of individuals with access to sensitive policy, political, and defence information.

The group is known under multiple tracking names across the industry: Callisto Group (F-Secure), COLDRIVER (Google TAG), TA446 (Proofpoint), ColdRiver, Dancing Salome, Recon 2, and UNC4057. Microsoft settled on Star Blizzard as the public-facing name in 2023, aligning with its broader practice of weather-themed naming for Russian state-linked actors.

What distinguishes Star Blizzard from noisier Russian APTs is tradecraft. Their intrusions do not begin with zero-days or novel malware. They begin with months of patient persona development on LinkedIn, tailored pretext emails that reference real conferences and real colleagues, and phishing infrastructure that passes a visual inspection from someone who has received similar legitimate emails dozens of times.

Threat Actor Profile

Attribution

Attribution to FSB Centre 18 rests on multiple evidentiary pillars. In December 2023, the US Department of Justice unsealed charges against two Star Blizzard operators identified by name: Ruslan Aleksandrovich Peretyatko, an FSB officer, and Andrey Stanislavovich Korinets, an operational support figure. The UK FCDO simultaneously sanctioned both individuals. The indictment describes a sustained campaign against hundreds of named targets across the US, UK, and allied governments, with the explicit goal of collecting foreign intelligence.

The FSB Centre 18 assessment reflects the group’s operational mandate — persistent access and intelligence collection rather than disruption or sabotage, which are more characteristic of GRU-attributed actors like Sandworm (Unit 74455) or Cadet Blizzard (Unit 29155). The FSB’s domestic counterintelligence mandate has long extended to monitoring foreign actors and influence operations, making civil society and NGO targeting a logical extension of the organisation’s existing work.

Target Profile

Star Blizzard’s targeting is highly selective and reflects specific intelligence collection priorities. Confirmed target categories, drawn from NCSC and CISA joint advisories, include:

Government and politics: Current and former officials in the US, UK, and European governments. Parliamentary and congressional staff. Political party officials and campaign staff.

Think tanks and policy research: Organisations conducting research on Russia, Ukraine, NATO, defence, energy policy, and election security. The Belfer Center, Atlantic Council, Chatham House, and similar institutions have been repeatedly targeted.

Academia: Researchers working on nuclear security, proliferation, arms control, and defence-related topics. Universities conducting research with defence funding or dual-use technology components.

Civil society and NGOs: Organisations supporting Ukrainian civil society, journalists documenting Russian human rights abuses, election integrity groups, and organisations documenting evidence of war crimes. Several organisations working on International Criminal Court prosecutions related to Ukraine have been targeted.

Media and journalism: Investigative journalists covering Russia, Ukraine, and Kremlin-linked financial networks. The targeting of journalists appears intended both for intelligence collection and to identify who is investigating which specific stories.

Defence industrial base: Companies and individuals with knowledge of weapons systems, classified programmes, or export control-relevant technology, particularly those with access to UK or US defence procurement.

TTPs and Tradecraft

Stage 1: Persona Development

Star Blizzard’s campaigns are distinguished by the investment made in establishing cover identities before any phishing attempt is made. The group creates detailed LinkedIn profiles — often presenting as academics, journalists, policy researchers, or conference organisers — and engages in sustained, credible interaction with their intended targets over weeks or months. They follow targets’ publications, comment on their posts, and build enough surface-level rapport that when direct contact comes, it is expected rather than surprising.

The initial LinkedIn message typically invites the target to review a paper, participate in an interview, attend a conference, or join a panel. Once the target expresses interest and the conversation moves to email, the phishing phase begins.

Stage 2: Credential Harvesting

Star Blizzard’s primary objective in most campaigns is not malware installation — it is credential theft to access email accounts. The group has used several credential harvesting approaches:

EvilGinx-style adversary-in-the-middle phishing proxies: Infrastructure that sits between the victim and their legitimate email provider, proxying the login flow in real time and capturing session tokens as well as passwords. This bypasses TOTP-based two-factor authentication because the session token is captured live, before it expires.

Custom phishing kits: Purpose-built login pages mimicking Gmail, Outlook, and ProtonMail. These are hosted on infrastructure registered to resemble legitimate organisations or services — for example, domains mimicking email security vendors, conference registration systems, or document review platforms.

OAuth phishing and app consent abuse: In more recent campaigns, the group has shifted toward OAuth consent phishing — directing victims to grant a malicious OAuth application access to their Google or Microsoft account. Because the victim is interacting with what appears to be a legitimate OAuth consent screen, the action feels less suspicious than entering credentials on an unfamiliar website. Critically, OAuth access persists even after a password change, making it a more durable access method.

Document lure delivery: Initial contact often includes a link to a Google Drive or OneDrive “document” — typically a PDF or Word file. The document either contains the phishing link itself, or is gated behind a credential page. Using legitimate cloud storage services to deliver lures increases deliverability past email security filters and creates an additional layer of trust.

Stage 3: Post-Compromise Activity

Following successful credential harvest, Star Blizzard’s operational pattern is patient and methodical:

  • Inbox monitoring: The compromised account is monitored for communications relevant to collection priorities. In some cases the actor maintains access silently for months without moving the intrusion to a more persistent foothold.
  • Contact mapping: Address books, email threads, and social connections are harvested to identify additional targets. Star Blizzard’s targeting of a single individual often leads to campaigns against their entire network of colleagues.
  • Document exfiltration: Attached documents, shared files, and cloud storage linked to the account are systematically reviewed and exfiltrated.
  • Forwarding rules: Persistent email forwarding rules are established to ensure continued collection even if the victim changes their password, until they specifically revoke access or check account activity.

The group generally does not deploy persistent malware in most intrusions — account access via credentials or OAuth tokens is preferred because it generates less suspicious activity, is harder to detect, and leaves fewer forensic artifacts on endpoint systems.

Infrastructure

Star Blizzard’s infrastructure patterns are well-documented across multiple NCSC and partner advisories:

  • Domain registration through commercial registrars (Namecheap, Porkbun) using privacy protection services
  • Domains designed to resemble legitimate organisations, conferences, government agencies, and email security products
  • TLS certificates from Let’s Encrypt and ZeroSSL — free, automated, and indistinguishable from legitimate use
  • Cloudflare and similar services used to add an additional layer of anonymity and infrastructure resilience
  • Infrastructure turnover is relatively frequent following public exposure, though the group has demonstrated the ability to rebuild and resume operations within weeks of disruptive actions

In December 2023, Microsoft and the NGO Information Sharing and Analysis Center (NGO-ISAC) obtained a court order to seize 180 Star Blizzard domains. The disruption affected operations but the group adapted and resumed targeting within the following months, rotating to new infrastructure.

Historical Incidents and Impact

UK political targeting (2022-2023): The NCSC confirmed that Star Blizzard targeted and compromised email accounts of UK politicians, civil servants, and senior defence officials. A tranche of communications between former Trade Secretary Liam Fox and campaign strategist Guo Wengui were leaked — though the Fox materials related to a different breach, the pattern of targeted UK political figure compromise is attributed to this actor.

NCSC advisory on US and UK targets (2023): A joint NCSC, CISA, FBI, and NSA advisory documented ongoing campaigns against US and UK government officials, defence contractors, and energy sector figures. The advisory described the group’s sophistication and noted that several organisations had been compromised through seemingly innocuous initial contact.

ICC targeting: Civil society organisations supporting International Criminal Court evidence collection for Ukraine-related war crimes prosecutions were confirmed as Star Blizzard targets, consistent with the group’s mandate to identify and monitor adversarial intelligence operations against Russia.

UK nuclear research: Cambridge University academics working on nuclear security and arms control have been specifically named as targets in the NCSC advisory — consistent with the group’s long-documented interest in Western nuclear posture and non-proliferation policy.

Defensive Implications

Star Blizzard’s campaign model is designed to defeat most standard enterprise security controls. The initial spearphishing chain involves no malware, no zero-day exploitation, and no network intrusion — it relies entirely on a human clicking a credible-looking link after being cultivated by a patient, sophisticated operator.

Phishing-resistant MFA is the most important single control. TOTP-based two-factor authentication does not stop AiTM phishing. Hardware security keys or passkeys (FIDO2/WebAuthn) do, because the key is cryptographically bound to the legitimate origin and cannot be replayed on an attacker-controlled proxy. High-value targets — executives, politicians, legal staff, think tank researchers, journalists — should be migrated to phishing-resistant MFA as a priority.

OAuth application review and conditional access. Regular audits of third-party OAuth applications with access to organisational email accounts should be standard. Conditional access policies can restrict which OAuth applications are permitted to connect, and can flag consent grants for administrative review.

Email forwarding rule monitoring. Star Blizzard commonly establishes forwarding rules to maintain persistent collection after initial account access. Monitoring for newly created forwarding rules, particularly those forwarding to external addresses, is a high-value detection opportunity. Microsoft Secure Score and Google Workspace Alerts include detection for this pattern.

NCSC Protective DNS and email authentication. UK organisations should enrol in NCSC’s Protective DNS service, which blocks known malicious domains at the resolver level. Email authentication — DMARC, DKIM, SPF — limits the group’s ability to spoof legitimate sender domains when approaching targets.

Target awareness for high-risk individuals. Star Blizzard’s initial approach via LinkedIn and professional networks is not technically complex — it requires no exploit. Awareness training specifically for high-value targets about unsolicited professional contact, document review requests, and conference invitations from unknown contacts is essential. The NCSC has published specific guidance for civil society organisations targeted by this group.

Account activity monitoring. Gmail and Microsoft 365 both provide recent access logs showing login locations and device activity. High-risk individuals should be encouraged to review these regularly and should have incident response guidance for cases where unexpected access is found.

The challenge Star Blizzard presents is not primarily a technical one. The actor’s sophistication lies in patience and social engineering, not in technical innovation. Defences that address the human layer — phishing-resistant authentication, target awareness, and access monitoring — are proportionately more important against this actor than against those whose campaigns rely on novel malware or zero-day exploits.