logo

Star Blizzard Operations Linked to Russian Intelligence Agency; APT28 Targets NATO’s Rapid Response

ID: a5e1d2d5-20fc-5a56-a3a3-5f0f402dab6d

STIX ID: report--a5e1d2d5-20fc-5a56-a3a3-5f0f402dab6d

Feed Name: EclecticIQ

Threat Score
85/100

Date Published: 2023-12-22

Date Updated: 2026-04-27

Author: Arda Büyükkaya

...
...

This report consolidates public intelligence on multiple active threats: Star Blizzard (FSB-linked) spear-phishing campaigns using credential- and session-cookie theft (EvilGinx) to compromise email and perform follow-on targeting; adversary abuse of AWS STS (AKIA/ASIA tokens) to gain persistence and lateral movement in cloud environments; and APT28 exploitation of Microsoft Outlook (CVE-2023-23397 and related bypass CVE-2023-29324) to exfiltrate Net-NTLMv2 hashes and enable relay attacks. The activity targets high-value sectors including NATO, government, defense, academia, and NGOs, and has been observed in the wild across multiple years.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.