Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
Star Blizzard used RedFlick phishing against 100-plus organizations and later deployed the CosmicPulse backdoor.
Field Effect says Star Blizzard, also known as ColdRiver and Callisto, ran at least 13 phishing campaigns from January through August 2026 against more than 100 organizations, chiefly in the United States and United Kingdom. Targets included government, diplomacy, research, policy, journalism, and finance groups involved in Ukraine-related work. Initial emails have no attachments; replies are followed by password-protected RAR or ZIP archives that may contain a VHDX disk or an LNK file disguised as a PDF. From April, RedFlick installers created scheduled tasks, enabled WebDAV, and deployed the CosmicPulse backdoor, a sequence Microsoft observed in at least one incident.