In a significant evolution of its cyber operations, the Russian state-sponsored threat actor known as Star Blizzard has refined its phishing tactics and malware delivery methods since January 2026. Microsoft reports that the group has shifted from targeted spear-phishing to large-scale phishing campaigns, utilizing a new malware delivery technique dubbed “RedFlick.” This change enhances their ability to evade detection and increases the likelihood of successful compromises, particularly against Ukrainian individuals and organizations, as well as international NGOs and think tanks involved in supporting Ukraine.
The RedFlick technique allows Star Blizzard to deploy its custom backdoor, CosmicPulse, with minimal user interaction. Unlike previous methods that required multiple actions from victims, RedFlick simplifies the infection process to a single user interaction. This operational shift, coupled with a broader phishing strategy, has reportedly enabled the group to target over 100 organizations, primarily in the United States and the United Kingdom, according to Microsoft’s analysis.
Star Blizzard’s Evolving Tactics
Star Blizzard, which is linked to the Russian Federal Security Service (FSB), has historically adapted its tactics to avoid detection. Recent observations indicate a move away from targeted spear-phishing towards mass phishing campaigns, leveraging compromised accounts on legitimate websites to send phishing emails. This approach not only broadens their reach but also enhances the credibility of their communications, making it more likely that targets will engage.
- Transition to large-scale phishing campaigns, sending hundreds of emails per operation.
- Utilization of compromised websites to create accounts for sending phishing emails.
- Modification of malware deployment methods to facilitate the installation of CosmicPulse.
Microsoft’s analysis highlights that these tactics have been particularly effective in targeting individuals and organizations involved in Ukraine-related policy discussions. The phishing campaigns have included lures themed around tax audits and invitations to high-profile discussions, often leading to the delivery of malicious attachments designed to initiate the RedFlick infection flow.
Phishing Campaigns and Malware Delivery
Throughout 2026, Microsoft has documented at least 13 distinct phishing campaigns attributed to Star Blizzard. These campaigns have evolved to include sophisticated techniques such as steganography to conceal malicious identifiers and the use of password-protected archives to deliver malware. For instance, a campaign in July 2026 involved a multi-stage execution chain where a password-protected ZIP file contained an LNK file that, when executed, downloaded a PDF from an actor-controlled server, ultimately leading to the installation of the CosmicPulse backdoor.
The RedFlick technique represents a notable advancement in Star Blizzard’s operational capabilities, allowing for greater stealth and efficiency in malware deployment. The group has also incorporated scheduled tasks to maintain persistence on infected systems, further complicating detection and remediation efforts.
Recommendations for Mitigation
In light of these developments, Microsoft advises organizations, particularly those in government, NGOs, and think tanks related to Ukraine, to adopt robust security measures. Key recommendations include:
- Implementing endpoint detection and response (EDR) solutions in block mode to prevent malicious artifacts from executing.
- Encouraging the use of web browsers that support advanced phishing protection features.
- Configuring automated investigation and remediation processes to quickly address alerts.
- Utilizing security defaults and conditional access policies to enhance identity security.
As Star Blizzard continues to adapt its tactics, organizations must remain vigilant and proactive in their cybersecurity strategies to mitigate the risks posed by these evolving threats.
For further insights into the evolving tactics of Star Blizzard and recommendations for defense, refer to the detailed analysis provided by Microsoft Security Blog here.


