---
title: "A Look at Russian State-sponsored Threat Actors and the Latest Evolving Tactics Targeting the UK, US, and Europe | DuoCircle"
description: "State-sponsored cyber threats from Russia are becoming increasingly prevalent and sophisticated."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-security/russian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe/"
---

Quick Answer

Russian state-sponsored groups (Seaborgium among them) are running spear-phishing campaigns against UK, US, and European targets, including parliamentary figures and academic researchers. The UK's National Cyber Security Centre issued an advisory naming Russia and Iran-based actors. Tactics observed: fake personas built across social media and academic profiles, lookalike credential-harvesting sites, and patient relationship-building before the malicious link is sent. Defenses that hold up: phishing-resistant MFA on email and SSO, link-scanning at click time, DMARC at enforcement to block direct-domain spoofing, and targeted training for executives, researchers, and policy staff who fit the actor's collection priorities.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-security%2Frussian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=A%20Look%20at%20Russian%20State-sponsored%20Threat%20Actors%20and%20the%20Latest%20Evolving%20Tactics%20Targeting%20the%20UK%2C%20US%2C%20and%20Europe&url=undefined%2Fblog%2Femail-security%2Frussian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-security%2Frussian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-security%2Frussian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe%2F&title=A%20Look%20at%20Russian%20State-sponsored%20Threat%20Actors%20and%20the%20Latest%20Evolving%20Tactics%20Targeting%20the%20UK%2C%20US%2C%20and%20Europe "Share on Reddit") [ ](mailto:?subject=A%20Look%20at%20Russian%20State-sponsored%20Threat%20Actors%20and%20the%20Latest%20Evolving%20Tactics%20Targeting%20the%20UK%2C%20US%2C%20and%20Europe&body=Check out this article: undefined%2Fblog%2Femail-security%2Frussian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe%2F "Share via Email") 

![Threat Actors](https://media.mailhop.org/duocircle/images/2023/04/dmarc-reporting-service-5759.jpg) 

_State-sponsored cyber threats from Russia_ [_are becoming_](/phishing-protection/small-businesss-shocking-response-to-cyber-threats/) _increasingly prevalent and sophisticated, with evolving tactics that challenge governments and organizations. In this text, we examine the **latest tactics** and their impact on the UK, US, and Europe. We also discuss the motives, potential consequences, and_ _**tips for** **mitigating** these threats\*\*.\*\*_

In recent years, **state-sponsored** cyber threats have become increasingly sophisticated and prevalent, and Russia is emerging as one of the leading actors in this field. Threat actors [create](https://vpnoverview.com/news/u-s-arrests-russian-man-accused-of-creating-nlbrute-malware/) fake personas through social media accounts, fake profiles, and academic papers to lure victims into replying to **phishing emails**.

They are [constantly](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) evolving their tactics, and governments and organizations are struggling to keep up. Hence, there are rising concerns regarding _individual privacy, national security, and critical infrastructure._

In the past 12 months, we saw increasing cases of Russian state-sponsored cyber criminals targeting **imminent personalities** in the UK, the US, and Europe. Taking note, the National Cyber Security Centre (NCSC) recently issued an [advisory warning](https://www.ncsc.gov.uk/news/uk-cyber-experts-warn-of-targeted-phishing-attacks-from-actors-based-in-russia-and-iran) about the rising cyberattacks associated with two cybercriminal gangs based in Iran and Russia. Let us start by discussing the latest attack by the group.

[![spear-phishing](https://media.mailhop.org/duocircle/images/2023/04/what-is-a-dmarc-5839.jpg)](https://media.mailhop.org/duocircle/images/2023/04/what-is-a-dmarc-5839.jpg)

## The Recent Attack Against MP Stewart McDonald at a Glance

In one of the recent attacks, a Russian hack group (Seaborgium) targeted the email account of a British Member of Parliament, Stewart McDonald. The group used a [spear-phishing](/content/spear-phishing-protection/spear-phishing-examples) technique and sent a **malicious email with a link** to a fake website. The hackers designed the website to harvest login credentials.

Security experts believe that the attack was part of a more comprehensive campaign by state-sponsored Russian attackers and highlights the **national security** threat and the need for governments to implement robust [cybersecurity](/) measures.

After the attack, the UK government issued a warning to MPs and their staff to enhance their security protocols and **remain vigilant** to potential [phishing attacks.](/content/phishing-prevention/phishing-email)

## Seaborgium: The Russian Threat Actors Behind the Attacks

Cybersecurity firms link Seaborgium, also known as Calisto, to a **malicious activity** likened to playing the game of “whack-a-mole.” It is due to the rapidity with which the threat actor registers and **changes personas** and aliases to mimic consumer email addresses and infrastructure, irrespective of success.

Sherrod DeGrippo, an independent threat intelligence expert, said that the Russian and Iranian threat actors had evolved their [social engineering](/phishing-protection/social-engineering-is-a-growing-threat/) tactics, which are now carefully constructed. They are creating more convincing complete personas, including _social media accounts, websites, and portals._

The threat actors refine their tactics with each successful attack by generating more convincing **fake profiles**. They are even developing phony webpages, websites, informational pieces, and papers to pose as researchers or journalists, making the techniques used in the attacks more elaborate and **sophisticated**.

## Seaborgium Targets: Why You Need to be on Guard

Academics are an attractive target for the [hacking group](https://thehackernews.com/2023/04/arid-viper-hacking-group-using-upgraded.html), as they usually have multiple roles besides being university professors.

For example, academics might serve on the board of intellectuals, work at a _law firm or hospital, and specialize in international law, atomic sciences, journalism, or activism_. Thus, [cybercriminals](https://www.thestreet.com/technology/cybercriminals-taken-down-in-international-fbi-sting) can compromise an academic in one area and **gain access to sensitive information**.

Furthermore, Journalists are also **high-value targets** as sensitive off-record material acquired from journalists is of significant value to Russian state-sponsored groups. Moreover, the intelligence they gain from journalists is timely, aiding the **malicious purposes** of these cybercriminal gangs.

## Seaborgium’s Latest Tactics: Everything You Need to Know

Although Seaborgium’s attack methods are not entirely unique, they have evolved and become increasingly sophisticated. Typically, their campaigns begin with **benign emails**, and only after confirming activity do they send [phishing emails](/content/phishing-prevention/phishing-email) containing malicious links that aim to collect sensitive information.

_In the past, Seaborgium has targeted the education sector, US federal civilian targets, and not-for-profit groups (NGOs) with geopolitical affiliations_. The group’s attacks rely heavily on **reconnaissance** and impersonation for delivery.

The NCSC advisory points out that Seaborgium’s tactics are similar to [TA453](https://thehackernews.com/2022/09/iranian-apt42-launched-over-30.html) but further explains that the two groups are **not working together** according to the NCSC’s industry reporting.

TA453, also known as APT42/ Yellow Garuda/ITG18/Charming Kitten, is an Iranian-based hacking group that uses techniques like **impersonation** and reconnaissance to collect sensitive information.

According to DeGrippo, also the former senior director of threat research and detection at Proofpoint, the tactics, techniques, and procedures employed by Seaborgium are **particularly insidious**. After logging in as a benign person and redirecting emails to their infrastructure, the [malicious actors](https://socradar.io/malicious-actors-in-dark-web-december-2022-ransomware-landscape/) continue to operate the compromised email account and remain undetected.

[![cyber espionage](https://media.mailhop.org/duocircle/images/2023/04/check-dmarc-record-7692.jpg)](https://media.mailhop.org/duocircle/images/2023/04/check-dmarc-record-7692.jpg)

## Is Russia Behind the Seaborgium Cybercriminal Gang?

> DeGrippo said that Seaborgium’s methods suggest that the state backs the threat actor. “The journalists have leaks, secrets, and sensitive information,” he said. The actor can also compromise the account and send emails posing as the victim. She added: “Because at that point, you start asking questions of sources of a particular interest to [cyber espionage](https://www.varonis.com/blog/what-is-cyber-espionage) intelligence for **Russian interests**.”

Microsoft’s Threat Intelligence Center, or MSTIC, tracking the group since its inception, says that Seaborgium is a **Russia-backed group** with objectives that align closely with Russian state interests.

Another reason the [Russian](https://www.ndtv.com/world-news/russian-hackers-preparing-new-cyber-assault-against-ukraine-report-3864856) establishments seem to back the threat group is that it coordinates the selection of targets with the events of the **Ukrainian war**. For example, it started targeting the defense sector when the topic of military aid and weapons delivery to Ukraine appeared in the news or when **nuclear energy-related targets** were chosen during on-the-ground battles around power plants.

## NCSC’s Recommendations: How to Stay Safe?

The NCSC advisory on Seaborgium suggests that the sophistication of the threat actor’s attacks has escalated and highlights the need for **heightened** **awareness** and protection measures for organizations, particularly those with **high levels of email traffic**.

Collaboration between different organizations in the security space is critical to producing an effective and **holistic method of tracking** and curtailing the activity of threat actors such as Seaborgium.

As part of a comprehensive cybersecurity strategy, it is recommended that email users are trained to **identify malicious emails** and that [email security](/content/email-security-services/types-of-email-security) tools are utilized to block threats before they reach users’ inboxes. Implementing robust multi-factor authentication on all possible systems would also help mitigate the impact of eventually stolen credentials.

## Final Words

The attack on the British MP is one of the many milestones of the [threat actor](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/). Last year, Seaborgium **targeted scientists** at three US nuclear research labs, Argonne, Brookhaven, and Lawrence. Thus, we saw how the **evolving tactics** of Russian state-sponsored threat actors present a significant challenge to the security of the UK, the US, and Europe.

_These attacks highlight the need for **continued vigilance** and investment in cybersecurity measures by governments and organizations._

While mitigating these threats is an ongoing challenge, continued research and collaboration between governments and the private sector can help to improve the understanding of these tactics and enhance the **ability to protect** against them. By doing so, organizations can take a proactive approach to cybersecurity and safeguard against the [growing threat](https://www.dailysabah.com/business/tech/growing-threats-prompt-investors-to-set-radar-on-cybersecurity-startups) posed by state-sponsored cyber actors.

## Topics

email securitySecurity 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  Email Security 12m  DMARC, SPF, and DKIM in 2026: Why Email Authentication Is Now a Regulatory Requirement, Not Just a Best Practice  Apr 29, 2026 ](/blog/dmarc-spf-dkim-2026-email-authentication-regulatory-requirement-best-practice/)[  Email Security 5m  Email Monitoring Tools: A Complete Guide to Protecting Your Email Ecosystem  May 7, 2026 ](/blog/email-monitoring-tools-guide-protecting-your-email-ecosystem-security/)[  Email Security 7m  10 Crucial Tips that Will Help You Avoid Spam Filters and Send Better Emails  Feb 14, 2023 ](/blog/email-security/10-crucial-tips-that-will-help-you-avoid-spam-filters-and-send-better-emails/)[  Email Security 15m  12 Best Hosted SMTP Servers for High Deliverability in 2026  Apr 8, 2026 ](/blog/email-security/12-best-hosted-smtp-servers-for-high-deliverability-in-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"A Look at Russian State-sponsored Threat Actors and the Latest Evolving Tactics Targeting the UK, US, and Europe","description":"State-sponsored cyber threats from Russia are becoming increasingly prevalent and sophisticated.","url":"https://www.duocircle.com/blog/email-security/russian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe/","datePublished":"2023-04-10T11:25:02.000Z","dateModified":"2025-05-29T11:19:03.000Z","dateCreated":"2023-04-10T11:25:02.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/russian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe/"},"articleSection":"email-security","keywords":"email security, Security","wordCount":1150,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/04/dmarc-reporting-service-5759.jpg","caption":"Threat Actors","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Security"},{"@type":"ListItem","position":3,"name":"A Look at Russian State-sponsored Threat Actors and the Latest Evolving Tactics Targeting the UK, US, and Europe","item":"https://www.duocircle.com/blog/email-security/russian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Security","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"A Look at Russian State-sponsored Threat Actors and the Latest Evolving Tactics Targeting the UK, US, and Europe","item":"https://www.duocircle.com/blog/email-security/russian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"A Look at Russian State-sponsored Threat Actors and the Latest Evolving Tactics Targeting the UK, US, and Europe","description":"State-sponsored cyber threats from Russia are becoming increasingly prevalent and sophisticated.","url":"https://www.duocircle.com/blog/email-security/russian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe/","datePublished":"2023-04-10T11:25:02.000Z","dateModified":"2025-05-29T11:19:03.000Z","dateCreated":"2023-04-10T11:25:02.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/russian-state-sponsored-threats-evolving-tactics-to-target-uk-us-and-europe/"},"articleSection":"email-security","keywords":"email security, Security","wordCount":1150,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/04/dmarc-reporting-service-5759.jpg","caption":"Threat Actors","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
