← Back to all threat actors

Star Blizzard

Also known as SEABORGIUM, Callisto Group, TA446, COLDRIVER
Tracked as G1033

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.

How we source and review actor profiles
Sectors
government, defense, ngo, research-academia
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1033

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: SEABORGIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Callisto Group

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TA446

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: COLDRIVER

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Star BlizzardCanonical Name
COLDRIVERAlias
Callisto GroupAlias
SEABORGIUMAlias
TA446Alias
G1033Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...