Threats · 6h ago
Microsoft says Star Blizzard has shifted since January to larger phishing runs and a new delivery method it tracks as RedFlick, affecting more than 100 organizations tied to Ukraine, NGOs, think tanks, governments, and related institutions. The group’s payload is CosmicPulse, a Windows backdoor.
RedFlick uses Windows scheduled tasks to pull in the backdoor after a single user interaction, instead of forcing victims through multiple steps as in the older ClickFix chain. That matters because the first email can be empty, the payload can arrive only after a reply, and the install happens automatically later, which makes the campaign easier to scale and harder to spot as a manual launch.
For defenders, the exposure now sits in the email-to-endpoint handoff: if an organization relies on one-click engagement to trigger trust, Star Blizzard’s method turns that into a quieter install path on Windows systems. Microsoft’s report also suggests the actor is broadening beyond a few tailored contacts into wider espionage sweeps.
3 sources covering this story
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft warns Russian threat group Star Blizzard is using new RedFlick phishing campaigns and CosmicPulse malware to target over 100 global organizations.
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Star Blizzard uses fake event invites and RedFlick scheduled tasks to install CosmicPulse on Windows systems tied to Ukraine.
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
Part of the PlainSec briefing for 2026-09-29