Russian hackers Star Blizzard expand phishing tactics targeting Ukraine and beyond

Published:

A group of Russian hackers known as Star Blizzard is expanding its phishing tactics, targeting governments, think tanks, and nonprofits globally, with a particular focus on Ukraine. Microsoft’s recent research highlights a shift in the group’s approach, utilizing a new malware delivery technique called RedFlick to enhance its operational reach.

Star Blizzard, linked to the Russian Federal Security Service (FSB), has transitioned from targeted spear-phishing to broader phishing campaigns, significantly increasing the volume of attacks. Microsoft observed that since January 2026, the group has conducted at least 13 large-scale phishing campaigns, initially focusing on Ukrainian entities but later expanding to targets worldwide. This shift suggests a testing phase for their new capabilities, as they adapt their strategies to maximize impact.

Middle East Relevance

While the primary focus of Star Blizzard’s recent activities has been on Ukraine and its allies, the implications of their tactics could resonate in the Middle East. Organizations in the region that engage with or support Ukraine may be at risk, particularly if they utilize similar digital infrastructures or communication platforms targeted by the group. However, the source does not establish any direct incidents or deployments within the UAE or GCC at this time.

Key Facts

  • Star Blizzard has shifted to larger-scale phishing campaigns, sending tens to hundreds of emails per operation.
  • Microsoft has tracked at least 13 distinct phishing campaigns since January 2026, primarily targeting NGOs and government organizations.
  • The RedFlick malware delivery technique allows for easier deployment of the custom backdoor, CosmicPulse.
  • Initial targets were in Ukraine, but the group has expanded its focus to include global entities.
  • Star Blizzard has been previously identified under various names, including SEABORGIUM and Callisto Group.

Technical Context

The RedFlick technique enhances the effectiveness of phishing attacks by requiring only a single user interaction for compromise, thereby reducing barriers to infection. This method involves initiating scheduled tasks that deploy the CosmicPulse backdoor, which is designed to evade detection. The campaigns often use lures related to exclusive events or financial notices to entice victims.

Risk and Decision

Organizations in the Middle East, particularly those involved in international relations or supporting Ukraine, should be vigilant against potential phishing attempts. The shift in Star Blizzard’s tactics indicates a broader threat landscape, necessitating proactive measures to safeguard sensitive information and communications. Stakeholders should assess their cybersecurity posture and consider implementing enhanced monitoring and response strategies to mitigate risks associated with these evolving threats.

Defensive Guidance

Organizations should prioritize user education on recognizing phishing attempts, particularly those that may involve invitations to events or financial solicitations. Regular updates to security protocols and monitoring for unusual email activity are essential. While specific patches or fixes were not provided in the source material, it is crucial for IT teams to stay informed about emerging threats and adapt their defenses accordingly.

Source and evidence

This report is based on research published by Microsoft, detailing the activities of the Star Blizzard hacking group and their evolving tactics as of September 2026. The findings highlight significant changes in their operational methods and the implications for global cybersecurity.

CWME will continue tracking regional implications as more verified information becomes available.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Check Point reports active exploitation of CVE-2026-85102 and CVE-2026-93616 vulnerabilities

Check Point has reported active exploitation of two critical vulnerabilities, CVE-2026-85102 and CVE-2026-93616, both with a CVSS score of 9.8. These pre-authentication flaws affect...

Dutch police arrest 24-year-old Pepijn van der Stap linked to ShinyHunters

Dutch authorities have arrested a 24-year-old man from Amsterdam, identified as Pepijn van der Stap, in connection with the notorious hacking group ShinyHunters. The...

Hiperdist appointed as authorized Huawei Cloud distributor in UAE

Hiperdist has been appointed as an authorized distributor for Huawei Cloud in the UAE, enhancing their collaboration in one of the Middle East's rapidly...

Citrix warns of active exploitation of vulnerabilities in NetScaler ADC and Gateway

Citrix has issued a security bulletin detailing eight vulnerabilities in its NetScaler ADC and Gateway products, with two—CVE-2026-88771 and CVE-2026-88772—confirmed as actively exploited. These...