Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft: FSB-linked Star Blizzard scaled RedFlick phishing to hundreds of emails per campaign, hitting over 100 mostly U.S. and U.K. organizations.
Microsoft reports that Star Blizzard, an FSB-affiliated espionage group also tracked as SEABORGIUM, Callisto Group, TA446, and COLDRIVER, shifted in 2026 to mass phishing campaigns of tens to hundreds of emails via an automated mass-mailing platform. The campaigns deploying new malware RedFlick affected over 100 organizations, primarily in the U.S. and U.K., plus Ukrainian government, NGO, and think-tank targets. RedFlick requires only a single user interaction and uses scheduled tasks to deploy the custom CosmicPulse backdoor. Microsoft observed at least 13 large-scale campaigns since January 2026, initially Ukraine-focused before expanding globally.