Russian State Hackers Use New RedFlick Technique to Push Malware
Microsoft said the Russian-linked group has run at least 13 large-scale phishing campaigns, affecting more than 100 organizations in the United States and United Kingdom.
- On Tuesday, Microsoft research identified that Star Blizzard, affiliated with the Russian Federal Security Service , is targeting over 100 organizations, primarily in the United States and United Kingdom, using new malware.
- Shifting from spear-phishing, the hackers launched large-scale campaigns; Microsoft observed at least 13 distinct operations since January 2026 targeting NGOs, think tanks, and government organizations worldwide.
- Star Blizzard deploys RedFlick, which Microsoft described as "a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse." The infection flow requires only single user interaction.
- Although initial attacks targeted Ukraine, the group now targets financial institutions and governments supporting Ukrainians, using phishing lures like fake event invites, tax audit notices, and fines.
- Previously identified under aliases including SEABORGIUM, Callisto Group, TA446, and COLDRIVER, Star Blizzard has been tracked by Microsoft since 2023 and 2025, with takedown efforts reported in 2024.
11 Articles
11 Articles
Star Blizzard expands event-invite intrusion campaign
Russia-linked Star Blizzard has targeted more than 100 organizations with fake event invitations designed to deliver a backdoor, extending a familiar social-engineering pattern into a broader cyber-espionage wave. The campaign used spoofed...
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft warns Russian threat group Star Blizzard is using new RedFlick phishing campaigns and CosmicPulse malware to target over 100 global organizations.
The Russian-sponsored hacker group Star Blizzard, also known in an expert environment under the names ColdRiver and Callisto, which Western intelligence agencies and government agencies link to the Russian Federal Security Service, has dramatically increased and scaled up their harmful activities in cyberspace.
Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations. The campaign replaces an obvious malicious attachment with a conversation that looks like ordinary professional correspondence. The activity was recorded in at least 13 campaigns from January through August 2026, chiefly affecting organizations in […]
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









