Threats · 6h ago

Star Blizzard Lowers the Cost of Espionage Phishing

Microsoft says Star Blizzard has shifted since January to larger phishing runs and a new delivery method it tracks as RedFlick, affecting more than 100 organizations tied to Ukraine, NGOs, think tanks, governments, and related institutions. The group’s payload is CosmicPulse, a Windows backdoor.

RedFlick uses Windows scheduled tasks to pull in the backdoor after a single user interaction, instead of forcing victims through multiple steps as in the older ClickFix chain. That matters because the first email can be empty, the payload can arrive only after a reply, and the install happens automatically later, which makes the campaign easier to scale and harder to spot as a manual launch.

For defenders, the exposure now sits in the email-to-endpoint handoff: if an organization relies on one-click engagement to trigger trust, Star Blizzard’s method turns that into a quieter install path on Windows systems. Microsoft’s report also suggests the actor is broadening beyond a few tailored contacts into wider espionage sweeps.

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-29

Editions

Related stories