Summary
- Microsoft has observed Star Blizzard running larger phishing campaigns than in its previous operations.
- RedFlick reduces the malware delivery chain to a single user interaction before deploying CosmicPulse.
- More than 100 organisations, primarily in the UK and US, were affected by the activity Microsoft observed.
Microsoft has documented a significant change in the operations of Star Blizzard, with the Russia-linked espionage group expanding beyond tightly targeted spear phishing and adopting a malware delivery technique designed to reduce the number of actions required from a victim.
The company’s threat intelligence researchers say they have observed the actor using larger initial-contact phishing campaigns throughout 2026 alongside a technique Microsoft calls RedFlick. The activity has targeted Ukrainian institutions, governments, financial organisations, think tanks, non-governmental organisations, researchers, and other groups associated with international policy and support for Ukraine.
Microsoft says more than 100 organisations have been affected, primarily in the United Kingdom and United States. The scale represents a change from Star Blizzard’s established preference for carefully constructed social-engineering operations directed at relatively narrow sets of individuals.
The actor is attributed by US authorities to Russia’s Federal Security Service Centre 18. Its previous operations have relied heavily on impersonation, relationship-building, credential theft, and phishing lures tailored to diplomats, researchers, politicians, journalists, and organisations involved in foreign and security policy.
RedFlick alters part of that operating model. Microsoft describes a delivery chain in which password-protected archives and malicious files ultimately create scheduled tasks used to deploy CosmicPulse, a Python backdoor associated with the actor. Compared with earlier ClickFix-style infection chains, the RedFlick process requires fewer actions from the target once the malicious attachment has been opened.
The phishing itself is also becoming less narrowly constrained. Microsoft observed campaigns sending tens or hundreds of emails at a time, with lures including invitations to closed discussions on European security, international finance, diplomacy, and Ukraine. One campaign impersonated a Chatham House conference, while others used purported invitations to policy forums and strategic discussions.
The combination couples familiar social engineering with greater scale. Star Blizzard has not abandoned targeted intelligence collection, but Microsoft’s evidence suggests the group is applying automation and repeatable infrastructure to reach a wider pool of people who work around its established areas of interest.
The use of compromised websites and accounts also complicates traditional assumptions about suspicious infrastructure. An email sent through previously legitimate infrastructure can be harder to distinguish from ordinary communications than one originating from a newly registered domain with little history.
Microsoft says it has continued to observe changes to Star Blizzard’s techniques after earlier campaigns were exposed publicly. That pattern is characteristic of an espionage operation adapting infrastructure, lures, execution chains, and persistence mechanisms while the underlying intelligence requirements remain broadly consistent.
The latest activity therefore represents more than a new malware name. Star Blizzard is retaining the political, diplomatic, and security-policy targeting associated with its previous campaigns while changing how widely it casts its initial net and how efficiently a successful lure can be converted into persistent access.





