Star Blizzard's RedFlick technique delivers CosmicPulse backdoor to 100+ organizations across 13 campaigns
Microsoft says Russia's Star Blizzard (FSB Centre 18) ran 13 mass phishing campaigns since January 2026, hitting 100+ mostly US/UK organizations supporting Ukraine with the single-click RedFlick loader that installs the Python-based CosmicPulse backdoor.
Microsoft reports that Russian state actor Star Blizzard — attributed by CISA as subordinate to the FSB's Centre 18 and also tracked as SEABORGIUM, Callisto Group, TA446, and COLDRIVER — has shifted since January 2026 from targeted spear phishing to large-scale campaigns, running at least 13 waves that have affected more than 100 organizations tied to supporting Ukraine, primarily in the United States and United Kingdom, as well as Ukrainian government, NGO, and think-tank targets. Campaigns were initially Ukraine-focused before expanding globally. Using an automated mass-mailing platform, the group now sends tens to hundreds of emails per wave from accounts on compromised websites, including hacked WordPress and cPanel email accounts, moving away from earlier Proton/free email accounts. Lures include fake Ukrainian tax-audit notices, payment notices, fines, closed-door policy roundtable invitations, and events posing as Chatham House and Atlantic Council functions. Targets who reply receive password-protected RAR/ZIP archives containing LNK files that fetch an MSI installer; a loader Microsoft tracks as RedFlick then creates three disguised scheduled tasks to install CosmicPulse, a custom Python-based backdoor, reducing infection to a single user interaction and replacing earlier multi-step ClickFix chains. One March 2026 campaign using an Atlantic Council lure instead delivered the DarkSword iPhone exploit kit. Microsoft published IOCs, detections, and hunting guidance; Defender detection names include Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse, and The Hacker News noted the domain secure-dns-hub[.]com was still active at publication time. One terminology difference: The Hacker News labels the 13 campaigns 'spearphishing,' while Microsoft and CyberScoop describe a deliberate shift away from targeted spear phishing toward mass campaigns.
- Attribution: Star Blizzard, a Russian state actor subordinate to the FSB's Centre 18 per CISA; also tracked as SEABORGIUM, Callisto Group, TA446, and COLDRIVER.
- At least 13 campaigns since January 2026; more than 100 organizations affected, primarily in the US and UK, tied to supporting Ukraine, plus Ukrainian government, NGO, and think-tank targets.
- Campaigns were initially Ukraine-focused before expanding globally; tens to hundreds of emails per wave sent via an automated mass-mailing platform.
- Infrastructure shift from Proton/free email accounts to hacked WordPress and cPanel email accounts on compromised websites.
- RedFlick loader reduces infection to a single user interaction: a password-protected RAR/ZIP archive with an LNK file fetches an MSI installer, then three disguised scheduled tasks deploy CosmicPulse, a custom Python-based backdoor,…
- Lures include fake Ukrainian tax-audit notices, payment notices, fines, exclusive event invitations, and closed-door policy roundtables posing as Chatham House and Atlantic Council events.
- One March 2026 campaign using an Atlantic Council lure delivered the DarkSword iPhone exploit kit instead of CosmicPulse.
- Microsoft Defender detection names: Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
Coverage timelineoldest first · each row is one article
- · 7h agoStar Blizzard refines phishing and malware delivery with the RedFlick technique
Microsoft Security Blog· 78
Microsoft details Star Blizzard's RedFlick technique delivering CosmicPulse backdoor via single-click phishing lures, hitting 100+ organizations supporting Ukraine.
- · 4h agoRussia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
The Hacker News· 75
Microsoft says Star Blizzard ran 13 fake-event-invite campaigns since January, hitting 100+ Ukraine-linked organizations with the CosmicPulse backdoor via scheduled tasks.
- · 2h ago