US authorities, in collaboration with Microsoft, have successfully disrupted a Russian hacking group targeting American officials and nonprofits. According to reports from Microsoft and US authorities, the hacking group, known as Star Blizzard, was linked to Russian intelligence and had aimed its cyber attacks at dozens of former military and intelligence officials, journalists, and civil society groups in the West.
The sophisticated campaign employed by Star Blizzard involved sending spear-phishing emails to its targets, appearing to be from a trusted source. These emails were designed to gain access to the victims’ internal systems with the intention of stealing information and disrupting their operations. The group conducted thorough research on its targets before launching attacks, demonstrating persistence and advanced tactics.
Star Blizzard not only targeted Western think tanks and individuals but also went after civil society groups, American military contractors, US companies, and the Department of Energy, which oversees various nuclear programs. In response to this threat, a US court has unsealed documents allowing Microsoft and the Department of Justice to seize over 100 website domain names associated with Star Blizzard.
While the effectiveness of Star Blizzard’s operations remains undisclosed, authorities anticipate continued cyber attacks from Russia against the US and its allies. Deputy Attorney General Lisa Monaco highlighted the Russian government’s involvement in this scheme to steal sensitive information from Americans and stressed the importance of relentless efforts to expose and counter Russian cyber actors.
Star Blizzard has been previously linked to Russia’s Federal Security Service (FSB) and has been under surveillance by Microsoft since 2017. The group has demonstrated adaptability and the ability to conceal its identity, presenting an ongoing challenge for cybersecurity professionals. US authorities have charged two Russian men in connection with Star Blizzard’s past activities, both believed to be in Russia.
In addition to targeting American entities, Star Blizzard extended its cyber attacks to Europe and other NATO countries, particularly those who supported Ukraine following Russia’s invasion. Requests for comments from the Russian Embassy in Washington were not immediately returned. The collaborative efforts between the US and Microsoft represent a significant step towards combating cyber threats and safeguarding sensitive information from malicious actors.