Star Blizzard Strikes 100+ Organizations Using Phishing and RedFlick Tactics

Microsoft Threat Intelligence has reported on the recent phishing and malware delivery activities conducted by Star Blizzard, a Russian state-sponsored threat group also known as Callisto Group or SEABORGIUM. This group is linked to Centre 18 of the Russian Federal Security Service, as noted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Since the beginning of January 2026, Microsoft has observed at least 13 major phishing campaigns targeting organizations globally, with over 100 entities affected, mainly located in the United States and the United Kingdom. These campaigns have zeroed in on Ukrainian individuals, government agencies, NGOs, and think tanks engaged in international policy matters. Notably, while the new campaigns have adopted broader phishing tactics, they still employ techniques that have been documented previously.

To facilitate widespread phishing efforts, Star Blizzard created accounts on compromised websites powered by platforms such as WordPress and cPanel. Microsoft has high confidence that these sites were specifically compromised for the purpose of launching phishing emails. Historically, the group relied on free email services, like ProtonMail and Microsoft consumer accounts, to carry out its attacks.

The latest campaigns show a strategic shift where Star Blizzard targeted multiple individuals within the same organization, crafting messages that mimic internal communications. Microsoft indicates that the group may have conducted preliminary testing of these advanced techniques against Ukrainian organizations before widening the scope of its phishing campaigns globally.

A significant development in Star Blizzard’s tactics is the introduction of a technique termed RedFlick. This method enables the creation of scheduled tasks that facilitate the deployment of their backend malware, known as CosmicPulse. Unlike previous ClickFix campaigns, which required multiple actions from victims, the new infection method can initiate with a single user interaction. Researchers at Microsoft have detected the use of password-protected ZIP or RAR files containing Virtual Hard Disk (VHDX) images and shortcut files disguised as legitimate documents.

This infection chain includes sophisticated components such as using SSH.exe with PermitLocalCommand to download and execute the malicious CosmicPulse downloader, alongside other tools like conhost.exe, curl, and PowerShell to fetch additional resources. In July, instances were reported where Base64-encoded PowerShell scripts were concealed within PDF files.

In their campaigns, Star Blizzard employed MSI installers to create scheduled tasks disguised as network operations. These tasks can transmit encoded data to command-and-control servers and execute commands via Control_RunDLL, while one task is specifically designed to retrieve and run the CosmicPulse downloader. This approach aligns with the group’s historical reliance on targeted spear-phishing, particularly against civil society organizations.

Star Blizzard’s recent activities underscore an evolution in their strategy, emphasizing large-scale phishing complemented by less interactive malware delivery mechanisms. This streamlined approach minimizes the steps necessary to deploy their malicious payloads. To counter such evolving threats, Microsoft advises organizations to implement phishing-resistant authentication, endpoint detection and response (EDR) in a blocking mode, as well as robust email and endpoint security controls.

In terms of MITRE ATT&CK tactics, the techniques observed include initial access, persistence, and execution, highlighting the sophisticated nature of Star Blizzard’s operations and underlining the significance of vigilance in cybersecurity practices for business owners.

Source