Threat actor · all actors
Star BlizzardG1033 state
🇷🇺 RU
aka Star Blizzard, SEABORGIUM, Callisto Group, TA446, COLDRIVER, Cold River, Nahr Elbard, Nahr el bared, Callisto, GOSSAMER BEAR, BlueCharlie, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, COLD RELIC
Last updated: 2026-08-20
About this actor
[Star Blizzard](https://attack.mitre.org/groups/G1033) is a cyber espionage and influence group originating in Russia that has been active since at least 2019. [Star Blizzard](https://attack.mitre.org/groups/G1033) campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.(Citation: Microsoft Star Blizzard August 2022)(Citation: CISA Star Blizzard Advisory December 2023)(Citation: StarBlizzard)(Citation: Google TAG COLDRIVER January 2024)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
Secureworkscolour-metal names
ProofpointTA threat-actor id
Recorded FutureTAG id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 31 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1059Command and Scripting Interpreter ↗T1059.007JavaScript ↗T1078Valid Accounts ↗T1114Email Collection ↗T1114.002Remote Email Collection ↗T1114.003Email Forwarding Rule ↗T1204User Execution ↗T1204.002Malicious File ↗T1539Steal Web Session Cookie ↗T1550Use Alternate Authentication Material ↗T1550.004Web Session Cookie ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1585Establish Accounts ↗T1585.001Social Media Accounts ↗T1585.002Email Accounts ↗T1586Compromise Accounts ↗T1586.002Email Accounts ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1589Gather Victim Identity Information ↗T1593Search Open Websites/Domains ↗T1598Phishing for Information ↗T1598.002Spearphishing Attachment ↗T1598.003Spearphishing Link ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1684Social Engineering ↗T1684.001Impersonation ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 15 / 31 | 48% |
SI-4 | 14 / 31 | 45% |
CM-2 | 12 / 31 | 39% |
CA-7 | 11 / 31 | 35% |
AC-4 | 10 / 31 | 32% |
SC-7 | 10 / 31 | 32% |
SI-3 | 10 / 31 | 32% |
SI-7 | 8 / 31 | 26% |
AC-3 | 7 / 31 | 23% |
SC-44 | 7 / 31 | 23% |
SI-8 | 7 / 31 | 23% |
IA-2 | 6 / 31 | 19% |
IA-9 | 6 / 31 | 19% |
AC-17 | 5 / 31 | 16% |
AC-6 | 5 / 31 | 16% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Silent Librarian 0.34
- EXOTIC LILY 0.33
- IndigoZebra 0.30
- WIRTE 0.28
- CURIUM 0.28
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00