The US and Microsoft seize 107 websites used by Russian intelligence agents and their proxies in the US operating under Star Blizzard, a group active since 2016
Microsoft and U.S. authorities have previously used court-backed domain seizures against state-linked operations, including a 2022 action that disrupted Russia-linked infrastructure used against Ukraine and a 2021 seizure of 42 domains tied to alleged Chinese espionage. This action extends that enforcement playbook to Star Blizzard.
The case also places civil-society targets—NGOs and journalists—at the center of public-private cyber disruption. Microsoft’s Digital Crimes Unit, NGO-ISAC, community partners and the Justice Department are presented as participants in the response.
First-order effects
The 107 seized websites are removed from Star Blizzard’s U.S.-based operating infrastructure, directly disrupting the group’s ability to use those properties against its targeted civil-society organizations.
Microsoft and its partners gain a court-backed mechanism to act alongside U.S. authorities, rather than relying only on detection and victim notifications.
Second-order effects
Star Blizzard will need to replace or reconfigure disrupted web infrastructure, while NGOs and journalists targeted by the group may need to watch for migration to new domains and related impersonation efforts.
The action reinforces a model Microsoft used in the Storm-1152 infrastructure seizure, encouraging providers and information-sharing groups to combine technical evidence with legal remedies against abusive online infrastructure.
Third-order effects
If such seizures continue, cyber defense is likely to become more institutionalized across platforms, threat-sharing groups and law enforcement, with disruption of adversary infrastructure becoming a recurring complement to organization-level security controls.
The approach can raise operational costs for state-linked actors, but its durable impact depends on whether legal actions can keep pace with attackers’ ability to shift infrastructure across providers and jurisdictions.
The trend: This is one instance of ecosystem cyber defense, in which private platforms and public authorities jointly use legal and technical tools to disrupt threat infrastructure before it reaches victims.
DOJ and Microsoft have partnered to seize 107 domain names that Russian intelligence operatives were using to spearphish and hack U.S. companies and current and former U.S. government employees. https://www.justice.gov/... https://blogs.microsoft.com/ ... https://www.noticeofpl…
DOJ and Microsoft take simultaneous action to seize >100 domains they say were used by FSB hacking unit to target civil society. Details alongside commentary from @natynettle and @jsrailton, who know this issue intimately.
Star Blizzard has continuously refined their detection evasion capabilities while remaining focused on email credential theft against the same targets. This blog provides updated technical information about Star Blizzard TTPs: https://www.microsoft.com/...
.@Microsoft's Digital Crimes Unit is actively disrupting Star Blizzard, a Russian actor targeting civil society groups around the world since 2022. We've seized 66 domains, collaborating with @TheJusticeDept to combat these cyber threats. https://blogs.microsoft.com/ ...
Excited to announce that we participated in @Microsoft's litigation aimed at seizing 66 domains of the Russian hackers STAR BLIZZARD (COLDRIVER) that we covered in our recent report w/ @citizenlab + @DeptFirst @TheJusticeDept also seized 41 domains https://www.accessnow.org/... […
UPDATE: @Microsoft's Digital Crimes Unit takes legal action to dismantle Russia-based threat actor COLDRIVER following our joint investigation with @accessnow. Read more: https://citizenlab.ca/...
The US District Court for the District of Columbia unsealed a civil action brought by Microsoft's DCU, including its order authorizing Microsoft to seize 66 unique domains used by Star Blizzard in cyberattacks targeting Microsoft customers globally, including throughout the US.
Today the #FBI announced the seizure of 41 internet domains in an operation to counter Russian spear-phishing efforts undertaken by Center 18 of the Russian Federal Security Service: https://www.justice.gov/...
It's time to face the consequences! We support @Microsoft + @NonprofitISAC's lawsuit against STAR BLIZZARD for facilitating cyber attacks against civil society by filing a legal statement featuring testimonies from victims impacted. https://www.accessnow.org/...
U.S. Justice Dept unseals warrant authorizing seizure of 41 Internet domains used by the FSB's “Callisto Group” and its proxies for “ongoing and sophisticated spear-phishing campaign” against American targets. Microsoft is going after 66 more domains. https://www.justice.gov/...
Microsoft's Digital Crimes Unit (DCU) is disrupting the technical infrastructure used by a persistent Russian nation-state threat actor that Microsoft tracks as Star Blizzard. https://blogs.microsoft.com/ ...
BREAKING: @Microsoft & @TheJusticeDept take simultaneous action against 🇷🇺Russian FSB-backed hacking group. #StarBlizzard/ #ColdRiver has been targeting a wide swath of US officials & civil society. Sweet moment because civil society played a key role in the lawsuit. Thanks to [i…
U.S. officials seize dozens of Internet domains (allegedly) used by the FSB and proxies to spearphish U.S. government computers and email accounts. ("Callisto Group," a.k.a. FSB's Center 18) https://www.justice.gov/...
DOJ and Microsoft seize > 100 web domains that Russia's FSB intel agency was allegedly using in hacking operations targeting current and former US officials & Russian citizens in the US: https://www.cnn.com/...
Foreign cyber influence campaigns are a big problem, but they aren't insurmountable. As early voting begins for the U.S. Presidential election, we must understand where information originates and protect ourselves against foreign attempts to deceive us. https://www.linkedin.com/.…