Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

Microsoft, DOJ Dismantle Domains Used by Russian FSB-Linked Hacking Group

The coordinated action resulted in the seizure of more than 100 domains used for spear-phishing targets in the US, UK, and Europe.

Russian hackers

Microsoft and the US Justice Department on Thursday announced the disruption of the technical infrastructure used by a Russian government-backed APT caught hacking specific targets in academia, defense, governmental organizations, NGOs and think-tanks.

The coordinated action resulted in the seizure of more than 100 domains used for spear-phishing lures against targets in the US, UK, and Europe and expanded the government’s exposure of the FSB-linked ‘Star Blizzard’ hacking operation.

Star Blizzard, publicly outed as a meticulous and relentless hacking team, is blamed for using sophisticated spear-phishing email lures against against civil society organizations and US Department of Energy facilities.

“Since January 2023, Microsoft has identified 82 customers targeted by this group, at a rate of approximately one attack per week,” the software giant said.

Star Blizzard is also known as Callisto Group/Coldriver and is known to target military personnel, government officials, think tanks, and journalists in Europe and the South Caucasus.  

In new documentation, Microsoft acknowledged the domain disruption won’t fully disrupt the group’s spear-phishing activities.  

Advertisement. Scroll to continue reading.

“While we expect Star Blizzard to always be establishing new infrastructure, today’s action impacts their operations at a critical point in time when foreign interference in U.S. democratic processes is of utmost concern,” the company said.

“Rebuilding infrastructure takes time, absorbs resources, and costs money. By collaborating with DOJ, we have been able to expand the scope of disruption and seize more infrastructure, enabling us to deliver greater impact against Star Blizzard,” Microsoft added.

As part of the collaboration, Redmond’s threat intelligence team say they can “quickly disrupt any new infrastructure we identify through an existing court proceeding.”

“[We] will gather additional valuable intelligence about this actor and the scope of its activities, which we can use to improve the security of our products, share with cross-sector partners to aid them in their own investigations and identify and assist victims with remediation efforts,” the company said.

Last year,  Five Eyes linked Star Blizzard to the Russian Federal Security Service (FSB) and exposed the actor’s attempted interference in UK politics through the targeting of elected officials, think tanks, journalists and the public sector. 

“Star Blizzard is persistent. They meticulously study their targets and pose as trusted contacts to achieve their goals,” Microsoft warned, noting that the group is particular about identifying high-value targets, crafting personalized phishing emails, and developing the necessary infrastructure for credential theft. 

“Once their active infrastructure is exposed, they swiftly transition to new domains to continue their operations,” Microsoft noted, urging civil society groups to use strong multi-factor authentication like passkeys on both personal and professional accounts, and enroll in Microsoft’s AccountGuard program for an additional layer of monitoring and protection from nation-state cyberattacks. 

Related: CISA Warns About Russian ‘Star Blizzard’ APT Spear-Phishing Operation

Related: Western, Russian Civil Society Targeted in Sophisticated Phishing Attacks

Related: European Union Sanctions Six Russian Hackers

Related: NATO Draws a Cyber Red Line in Tensions With Russia

Written By

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a security community engagement expert who has built programs at major global brands, including Intel Corp., Bishop Fox and GReAT. Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.