Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Microsoft
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
A group of Russian government hackers is refining its attacks to make it easier to eavesdrop on victims and significantly expand its targets among governments, think tanks and nonprofits around the world, with an emphasis on Ukraine, Microsoft research published Tuesday concludes.
The company examined a change in the approach of a group it calls Star Blizzard, which is affiliated with the Russian Federal Security Service (FSB), and its novel malware, RedFlick.
“In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns,” Microsoft wrote in a blog post. “The larger-scale phishing operations were observed at a scale not previously seen from the actor, ranging from tens to hundreds of email messages per campaign. This change likely reflects the actor’s adoption of a mass-mailing phishing platform to automate campaign execution and increase the likelihood of successful compromises by significantly expanding the initial targeting pool.”
Microsoft said the RedFlick campaigns have targeted Ukrainians, as well as financial institutions and governments that have supported Ukraine. It said it has seen the activity affect over 100 organizations that are primarily in the United States or United Kingdom.
One of the things that makes RedFlick effective isn’t just its pure volume, but the fact that its “infection flow only requires a single user interaction, reducing friction in the compromise process,” the company said in its blog post.
The most common phishing lure is inviting potential victims to exclusive events, but it also solicits its targets with information about supposed tax audits, payment notices and fines.
“Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide,” the company wrote.
The initial targets were in Ukraine but by spring it was going after those outside the nation it invaded in 2022. “The actor’s shift from Ukraine-focused operations to global targets could indicate Star Blizzard initially targeted Ukraine to test their new capabilities,” Microsoft wrote.
RedFlick has been a key adaptation as “a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor’s custom backdoor, CosmicPulse,” the company said.
This isn’t the first time that Microsoft has called out Star Blizzard, with past observations coming in 2023 and 2025 and takedown efforts coming in 2024.
Star Blizzard has been known by other names as well: SEABORGIUM, Callisto Group, TA446 and COLDRIVER.
Latest Podcasts
Government
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
ShinyHunters trades financial extortion for a reckless war of ego with the FBI
Supreme Court permits states to use SAVE database for citizenship checks
Technology
New bill would create federal investigative body for AI-driven hacks
CISA outlines improvement plan for CVE program
Researchers use AI to find widespread software decoder flaw
The AI hacking apocalypse is not inevitable
Threats
Kiteworks lifts shutdown advisory after 'credible threat intelligence' from federal authorities
Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Policy
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
The president has called for AI leadership. Here’s the mission.
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
Originally published by CyberScoop. © CyberScoop. Written by Tim Starks.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-29 20:01 UTC
Related stories
- ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th)
SANS Internet Storm Center · 2026-09-30
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
CyberScoop · 2026-09-29
- Former US Air Force members sent to prison over BEC attacks
BleepingComputer · 2026-09-29
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
The Hacker News · 2026-09-29
- RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
Infosecurity Magazine · 2026-09-29