Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
FSB-linked Star Blizzard expanded phishing, hitting over 100 organizations with RedFlick and the CosmicPulse backdoor.
Microsoft reported that Star Blizzard, also known as Callisto and ColdRiver and linked to Russia's FSB, has run at least 13 large phishing campaigns since January 2026 against more than 100 organizations, mainly in the United States and the United Kingdom, plus Ukrainian targets and Ukraine supporters. The group now sends password-protected archives that trigger RedFlick, which uses scheduled tasks to install the CosmicPulse backdoor, replacing the multi-step ClickFix method. Earlier lures impersonated Ukrainian tax authorities via Ukr.net; later waves used fake conference invitations and accounts on compromised websites.