A Russian state-backed hacking group spent a year targeting American nuclear scientists, defense contractors, and government employees, according to a joint intelligence warning issued by the US and its allies. The group, known as Star Blizzard (or Cold River, depending on which threat intelligence firm you ask), reportedly sharpened its techniques on Ukrainian targets first before turning its attention westward.

The advisory, published on July 23-24, 2026, describes a methodical espionage campaign focused on organizations involved in nuclear fusion research. No breaches of critical nuclear infrastructure were reported.

How the campaign worked

Star Blizzard’s playbook centered on credential-harvesting phishing attacks, primarily aimed at Zimbra mail servers. The group refined its approach on Ukrainian governmental and military targets first before pivoting to Western institutions tied to nuclear research and defense.

This isn’t Star Blizzard’s first appearance on the threat radar. The group was previously linked to phishing attempts against US national laboratories during 2022-2023. The latest campaign represents an escalation in both scope and sophistication, with intelligence agencies noting that the targeting pattern reveals a clear priority: gathering intelligence on Western nuclear capabilities and the national security frameworks surrounding them.