National Cyber Security Centre Advisory: Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns

National Cyber Security Centre Advisory: Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns

Updated and new research, updated vulnerabilities, security updates and revised actors.

Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns 

The Russia-based actor is targeting organisations and individuals in the UK and other geographical areas of interest

Overview

The Russia-based actor Star Blizzard (formerly known as SEABORGIUM, also known as Callisto Group/TA446/COLDRIVER/TAG-53/BlueCharlie) continues to successfully use spear-phishing attacks against targeted organizations and individuals in the UK, and other geographical areas of interest, for information-gathering activity.

The UK National Cyber Security Centre (NCSC), the US Cybersecurity and Infrastructure Security Agency (CISA), the US Federal Bureau of Investigation (FBI), the US National Security Agency (NSA), the US Cyber National Mission Force (CNMF), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the Canadian Centre for Cyber Security (CCCS), and the New Zealand National Cyber Security Centre (NCSC-NZ) assess that Star Blizzard is almost certainly subordinate to the Russian Federal Security Service (FSB) Centre 18.

Industry has previously published details of Star Blizzard. This advisory draws on that body of information.

This advisory raises awareness of the spear-phishing techniques Star Blizzard uses to target individuals and organisations. This activity is continuing through 2023.