Seaborgium

Threat Actor Profile Updated a month ago
Download STIX
Preview STIX
Seaborgium, also known as Star Blizzard, Callisto Group, COLDRIVER, and TAG-53, is a threat actor linked to suspected Russian threat activity groups. Open-source reporting has enabled Insikt Group to profile the infrastructure used by this group, revealing significant overlaps with other known malicious entities. On August 15, 2022, a collaborative report by Microsoft, Google’s Threat Analysis Group (TAG), and Proofpoint’s Threat Research Team shed light on Seaborgium's ongoing phishing operations. This group has been active since at least 2015, targeting government officials, military personnel, journalists, and think tanks. The hacking group has been responsible for a nearly decade-long spear-phishing campaign against British lawmakers across multiple political parties and the leak of classified documents. Both Microsoft and the UK government have assessed that another entity, Blue Charlie, is linked to Seaborgium. The group has consistently set up its infrastructure in a way that bears significant similarities to those attributed to the Callisto Group, COLDRIVER, and SEABORGIUM, indicating a coordinated effort or shared resources among these entities. The US and UK governments have identified the Callisto Group, which is also known as Seaborgium, Coldriver, Star Blizzard, TA446, and TAG-53, as being linked to Russia’s Federal Security Service (FSB), specifically its Center 18 cyberespionage unit. Cybersecurity researchers at Microsoft's Threat Intelligence team have unveiled that this Russian state-sponsored actor has increased its sophistication and developed new evasion techniques to utilize in ongoing attacks. The group's successful email breaches enable it to carry out various malicious activities, highlighting the gravity of the situation.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
COLDRIVER
6
Coldriver, also known as Callisto Group and Star Blizzard, is a threat actor believed to originate from Russia. This entity is recognized for its malicious activities including disinformation campaigns, spear-phishing attacks, and the use of custom malware. The group has been associated with the Rus
Callisto Group
4
The Callisto Group, a threat actor identified as part of the Russian Federal Security Service, has been exposed by the United States and the United Kingdom for its malicious cyber activities. This group, also known as Coldriver and formerly tracked by Microsoft under the moniker "Seaborgium," is com
Bluecharlie
4
BlueCharlie, also known as TAG-53, Blue Callisto, Callisto (or Calisto), COLDRIVER, Star Blizzard (formerly SEABORGIUM), and TA446, is a threat actor that has been linked to Russia and has reportedly been active since 2019. The group has been involved in various malicious activities including cybere
Callisto
4
Callisto, also known as Gossamer Bear, COLDRIVER, UNC4057, Star Blizzard, Blue Charlie, and SEABORGIUM, is a threat actor linked to the Russian state. This group, which has been tracked by various entities including Microsoft, Google's Threat Analysis Group (TAG), and Insikt Group, is known for its
Star Blizzard
3
Star Blizzard, also known as Seaborgium or the Callisto Group, is a threat actor linked to Russia's intelligence service, the FSB. The group has been involved in sophisticated cyber-attacks worldwide, primarily using spear-phishing campaigns to steal account credentials and data. Microsoft, which tr
TA446
3
TA446, also known as the Callisto APT group, Seaborgium, Star Blizzard, ColdRiver, TAG-53, and BlueCharlie, is a threat actor that has been active since at least 2015. This cyberespionage entity has persistently targeted individuals and organizations involved in international affairs, defense, and l
Calisto
2
Calisto, also known as BlueCharlie, Blue Callisto, TAG-53, COLDRIVER, Star Blizzard (formerly SEABORGIUM), TA446, and UNC4057, is a threat actor that has been active since 2019. This group targets a wide range of sectors and is particularly focused on individuals and organizations involved in intern
Starblizzard
2
None
Cold River
1
Cold River, a sophisticated threat actor linked to the Kremlin, has been engaging in malicious cyber activities for several years. The group, also known as Star Blizzard, Callisto, and UNC4057, is attributed to Center 18 of the FSB, one of Russia's security services sponsoring global cyber espionage
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Phishing
Blizzard
Russia
Apt
NCSC
Uk
Reconnaissance
State Sponso...
Microsoft
Outlook
Domains
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
TA453Unspecified
2
TA453, also known as Charming Kitten, APT35, Phosphorus, and Ballistic Bobcat, is a threat actor attributed to the Iranian government. This group has been involved in numerous cyber espionage campaigns against various entities worldwide, with notable incidents involving an attack on a close affiliat
Blue CharlieUnspecified
1
Blue Charlie, also known as TAG-53, UNC4057, Star Blizzard, and Callisto, is a threat actor linked to Russian threat activity groups such as the Callisto Group, COLDRIVER, and SEABORGIUM. Both Microsoft and the UK government have assessed this connection. The entity is believed to be part of the wid
Callisto Apt GroupUnspecified
1
None
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
Seaborgium CallistoUnspecified
1
None
Source Document References
Information about the Seaborgium Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
BankInfoSecurity
a month ago
European Union Sanctions Russian State Hackers
Krebs on Security
2 months ago
Stark Industries Solutions: An Iron Hammer in the Cloud
CERT-EU
6 months ago
Russian FSB Hacking Group Turns to Malware | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
BankInfoSecurity
6 months ago
Google: Russian FSB Hacking Group Turns to Malware
Securityaffairs
6 months ago
Google TAG warns that Russian COLDRIVER APT is using a custom backdoor
CERT-EU
7 months ago
Microsoft Alert: COLDRIVER Credential Theft Rising Again
CERT-EU
7 months ago
UK names Russian FSB agents behind political hacking campaign | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
7 months ago
Russian Star Blizzard New Evasion Techniques to Hijack Email Accounts
CERT-EU
7 months ago
Russian cyber-spies identified in APT attacks against UK democracy
CERT-EU
7 months ago
US, UK accuse Russia’s Callisto Group of cyber espionage, political interference
CERT-EU
7 months ago
Russian FSB Targets US and UK Politicians in Sneaky Spear-Phish Plan
CERT-EU
7 months ago
USA & Britain Accuse Russia Of Hacking
CERT-EU
7 months ago
UK government takes steps to thwart Russia's FSB hackers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
7 months ago
UK accuses Russia of cyber interference targeting elections and democracy
CERT-EU
8 months ago
UK and US expose Russia Callisto Group's activity and sanction members
CERT-EU
8 months ago
US charges two Russians in hacks of government accounts | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
8 months ago
UK and allies expose Russian FSB hacking group, sanction members
BankInfoSecurity
8 months ago
UK and US Accuse Russian FSB of 'Hack and Leak' Operation
CERT-EU
8 months ago
Russia's FSB Hacking UK Politicians NCSC | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
InfoSecurity-magazine
8 months ago
UK Government Warns of Russian Cyber Campaigns Against Democracy