Malware development overview | Image: Google Threat Intelligence Group
Since January 2026, a Russian state hacking group has sent at least 13 large phishing waves to think tanks, NGOs, and governments. Microsoft Threat Intelligence tracks the group as Star Blizzard. In its new report on the Star Blizzard RedFlick technique, Microsoft says the campaigns have hit more than 100 organizations, mostly in the US and UK.
At a Glance
| Actor | Star Blizzard (also known as Callisto, COLDRIVER, SEABORGIUM), linked to Russia’s FSB Centre 18 |
| Activity | Mass phishing and malware delivery for cyberespionage |
| Targets | Ukrainian individuals, NGOs, think tanks, governments, and financial institutions that support Ukraine |
| Scale | 100+ organizations affected; 13+ campaigns since January 2026 (Microsoft figures) |
| Law enforcement | Two alleged members charged in the US in 2023; domains seized in 2024; no new action announced |
| Sources | Microsoft Threat Intelligence; U.S. Department of Justice |
TL;DR
Star Blizzard has moved from careful one-to-one spear phishing to campaigns with hundreds of emails. A new delivery method, RedFlick, uses scheduled tasks to install the CosmicPulse backdoor after just one click. The targets remain supporters of Ukraine.
What Happened
From Spear Phishing to Mass Mailing
For years, Star Blizzard wrote tailored emails while posing as known diplomats or experts. In 2026, it also began sending “tens to hundreds of email messages per campaign.” Microsoft believes the group adopted a mass-mailing platform to widen its reach.
The first waves, in January and February, hit Ukrainian users with fake tax audit and fine notices. From March, the lures turned global. Many posed as invitations to closed-door events at well-known think tanks and forums. Others copied internal messages from the target’s own organization. Microsoft suggests the group may have used Ukraine as a test bed first.
Hijacked Websites as Mail Senders
Previously, the group used free accounts on Proton Mail and Microsoft consumer services. Since March, it has sent mail from accounts created on compromised CPanel and WordPress sites instead. Microsoft “assesses with high confidence that these websites have been compromised by Star Blizzard for this purpose.”
How RedFlick Works
Once a target replies, the group sends a password-protected ZIP or RAR file. Notably, the password arrives as an image, which helps it slip past scanners. Inside sits a shortcut file disguised as a PDF.
Opening it quietly installs an MSI package. By April, that package created three scheduled tasks posing as network tools. One sends the computer and user name to the attackers. Another sets up WebDAV so Windows can fetch remote files over HTTP. The third runs a CosmicPulse downloader disguised as a Control Panel applet.
This marks a change from the group’s older ClickFix lures, which needed several victim actions. In contrast, “the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process.”
Payloads Hidden in PDFs
In July, the group added another layer. A shortcut file downloaded a PDF that hid an encoded command inside. That command fetched a fresh MSI installer. Then, in mid-August, one campaign used steganography to hide identifiers.
Who Is Behind It
Microsoft attributes the activity to Star Blizzard, a group US authorities tie to FSB Centre 18. This is a vendor attribution backed by earlier government findings. In December 2023, the US Justice Department charged two Russian nationals over the group’s alleged hacking. Prosecutors described one as an FSB Centre 18 officer. Neither has faced trial.
Then, in October 2024, the DOJ seized 41 domains used by the group. At the same time, Microsoft moved to restrain 66 more through a civil action. Clearly, those steps did not stop the group. Microsoft notes that Star Blizzard “periodically overhauls” its methods after public exposure.
Impact and Scale
Microsoft counts more than 100 affected organizations. Targets include diplomats, researchers, journalists, parliament staff, and financial groups that aided Ukraine. Even Kyiv hotels received fake water-shutdown notices. Once installed, CosmicPulse gives the attackers a Python-based backdoor on the victim’s machine. The group also used a separate iOS backdoor, DarkSword, in one March campaign.
How to Stay Protected
The Star Blizzard RedFlick chain relies on familiar Windows tools. Therefore, defenders can spot it with the right monitoring:
- Treat unexpected event invitations with caution, even from known organizations.
- Block password-protected archives from outside senders, or send them for review.
- Alert on new scheduled tasks that call control.exe or WebDAV paths.
- Watch for shortcut files that launch curl, SSH, or hidden console windows.
- Flag MSI installs that follow the opening of an email attachment.
- Use phishing-resistant MFA for staff in policy, diplomatic, and NGO roles.
Microsoft sums up the trend plainly. The group aims to “streamline malware deployment, reduce required user interaction, and improve operational scalability.” For Ukraine’s supporters, that means more phishing emails are likely on the way.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!