threatintel
actor tracker
COLDRIVER
Sanctionseverity: High2023-12-07

UK NCSC + DOJ publicly attribute Star Blizzard to FSB Centre 18

published by UK National Cyber Security Centre
Actor
COLDRIVERRU · RussiaAPT

Russian state-sponsored intrusion set publicly assessed by the UK NCSC and Five Eyes partners as 'almost certainly subordinate to FSB Centre 18'. Conducts targeted credential-phishing operations agai…

Summary

The UK NCSC and Five Eyes partners issued a joint advisory assessing that COLDRIVER (Star Blizzard / Callisto / SEABORGIUM) is 'almost certainly subordinate to FSB Centre 18'. The UK Foreign Office concurrently sanctioned two named operators, and the U.S. DOJ unsealed an indictment of FSB officer Ruslan Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets for spear-phishing campaigns against U.S., UK, NATO, and Ukrainian targets.

Tags

fsbspear-phishingfive-eyessanctions

Primary source

ncsc.gov.uk