# Star Blizzard

> As of 2026-09-30, Star Blizzard is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning apt. ATT&CK coverage spans 28 techniques across 10 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036.005 (Match Legitimate Resource Name or Location), T1053.005 (Scheduled Task).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** APT
- **As of:** 2026-09-30

## ATT&CK techniques observed

28 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (11), Execution (4), Resource Development (3), Command and Control (2), Credential Access (2), Discovery (2).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 2 of 2 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 2 tracked threats
- [T1059.003](https://intel.threadlinqs.com/technique/T1059.003) Windows Command Shell — Execution — observed in 2 of 2 tracked threats
- [T1059.006](https://intel.threadlinqs.com/technique/T1059.006) Python — Execution — observed in 2 of 2 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 2 tracked threats
- [T1112](https://intel.threadlinqs.com/technique/T1112) Modify Registry — Defense Impairment — observed in 2 of 2 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 2 of 2 tracked threats
- [T1218.002](https://attack.mitre.org/techniques/T1218/002/) Control Panel — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1218.007](https://intel.threadlinqs.com/technique/T1218.007) Msiexec — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1566.001](https://intel.threadlinqs.com/technique/T1566.001) Phishing: Spearphishing Attachment — Initial Access — observed in 2 of 2 tracked threats
- [T1027.003](https://intel.threadlinqs.com/technique/T1027.003) Steganography — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats

## Tracked threats

- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — HIGH
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Star%20Blizzard
