Star Blizzard Lowers the Cost of Espionage Phishing
Microsoft says Star Blizzard has shifted since January to larger phishing runs and a new delivery method it tracks as RedFlick, affecting more than 100 organizations tied to Ukraine, NGOs, think tanks, governments, and related institutions. The group’s payload is CosmicPulse, a Windows backdoor.
RedFlick uses Windows scheduled tasks to pull in the backdoor after a single user interaction, instead of forcing victims through multiple steps as in the older ClickFix chain. That matters because the first email can be empty, the payload can arrive only after a reply, and the install happens automatically later, which makes the campaign easier to scale and harder to spot as a manual launch.
For defenders, the exposure now sits in the email-to-endpoint handoff: if an organization relies on one-click engagement to trigger trust, Star Blizzard’s method turns that into a quieter install path on Windows systems. Microsoft’s report also suggests the actor is broadening beyond a few tailored contacts into wider espionage sweeps.
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft warns Russian threat group Star Blizzard is using new RedFlick phishing campaigns and CosmicPulse malware to target over 100 global organizations.
Star Blizzard refines phishing and malware delivery with the RedFlick technique | Microsoft Security Blog
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.