CYOPS · Cyber Operations

Star Blizzard Trades Precision for Volume: Thirteen Campaigns, One Click

Microsoft counts at least thirteen large-scale phishing campaigns and more than one hundred affected organisations since January. The change that matters is not the new malware but that an actor known for narrow spear-phishing is now running volume.

What Microsoft reported

On 29 September, Microsoft Threat Intelligence published research on a delivery technique it names RedFlick, used by the Russian state actor it tracks as Star Blizzard. The headline figures are deliberately plain: “at least 13 distinct large-scale phishing campaigns” between January and August 2026, affecting “over 100 organizations primarily in the United States and United Kingdom”, with campaigns ranging from “tens to hundreds of email messages per campaign” [1].

Targeting is described as Ukrainian individuals and institutions along with international non-governmental organisations, Western think tanks, governments and financial institutions connected to international policy, “particularly those with a nexus in supporting Ukraine” [1]. Independent reporting adds that activity began against Ukrainian recipients and widened internationally from around March, which Microsoft reads as the actor testing a new capability before scaling it [2].

The shift that actually matters

Star Blizzard has a long public record as a precision actor. The eight-agency joint advisory of December 2023 describes a group that uses “open-source resources to conduct reconnaissance, including social media and professional networking platforms”, creates email accounts impersonating known contacts, builds trust over time, and on gaining mailbox access sets up “mail-forwarding rules, giving them ongoing visibility of victim correspondence” [8]. That is patient, researched, one-target-at-a-time work against academia, defence, government, NGOs, think tanks and politicians [8][11].

What Microsoft documents is the same actor running campaigns of hundreds of messages. This is the finding a defender should take away, because it inverts a widely held planning assumption. Many organisations treat state espionage actors as a low-volume, high-selectivity threat to a named handful of staff, and treat bulk phishing as a commodity problem for the mail gateway. An actor that does both at once sits in neither bucket.

The mechanism behind the shift is friction. Microsoft notes that the earlier approach, which relied on ClickFix-style lures, “required several actions by the victim before deploying CosmicPulse”, whereas “the RedFlick infection flow only requires a single user interaction” [1][4]. Fewer steps means a higher proportion of delivered messages convert, which is what makes volume worth the operational cost of sending it.

Piyush Sharma, co-founder and chief executive of Tuskira, framed the same point in operator terms when speaking to Dark Reading about the chain:

What interests me about RedFlick is how much work it takes away from the victim.

Piyush Sharma, Tuskira, quoted by Dark Reading [4]

The chain, at the level that matters

The published description supports detection without reproducing anything useful to an attacker. A phishing message delivers or links to a password-protected RAR or ZIP archive; Microsoft notes the password is supplied in a form that hinders automated inspection [1][7]. The archive contains either a virtual hard disk image shipping a shortcut file disguised as a PDF, or the shortcut directly [1][3]. Opening it runs a script through standard Windows components while a decoy document is displayed [1][3].

From April 2026, the installers began creating scheduled tasks. Microsoft names three: “Internet Quality Test Connection”, “Network Configuration Manager” and “System Health Monitor” [1][6]. Between them they collect basic host and network identifiers, enable Web Distributed Authoring and Versioning access, and fetch the next stage [5][6]. A Control Panel applet downloader, which Microsoft notes is “known publically as NOROBOT or BAITSWITCH”, retrieves the backdoor [1].

CosmicPulse itself is a Python backdoor, also tracked as YESROBOT, delivered alongside a bundled Python runtime, with its payload decrypted using a key held in the registry and recovered in AES-ECB mode [1][3]. Its documented function is to run attacker-supplied Python to download and execute files or retrieve documents from the host [3]. Microsoft reports observing the full sequence through to CosmicPulse deployment “in at least one incident” [5][6] — a careful phrasing worth preserving, because it distinguishes the scale of the phishing from the confirmed scale of the backdoor.

Sending from other people’s websites

The infrastructure detail with the widest consequence is the sending path. Microsoft states that “Since March 2026, Star Blizzard has made another notable change” by using accounts created on compromised websites to send phishing email, that those sites were hosted on cPanel and WordPress, and that Microsoft assesses “with high confidence that these websites have been compromised by Star Blizzard for this purpose” [1].

For the recipient’s defences, this degrades reputation-based filtering: mail arrives from established domains with no prior association with the actor. For the owners of those sites, a commodity-hosted content site becomes the sending leg of a state espionage campaign at near-zero cost to the operator. Any organisation running a marketing site, a conference site or a community forum on commodity hosting is a candidate, and most such sites are outside the security team’s inventory.

Whose assessment, and how strongly worded

Microsoft does not offer its own attribution sentence. It reports someone else’s: “Star Blizzard is attributed by the United States Cybersecurity and Infrastructure Agency (CISA) as subordinate to the Russian Federal Security Service Centre (FSB) Centre 18” [1].

The underlying judgement is in the December 2023 joint advisory, issued by the UK NCSC with CISA, the FBI, the NSA, US Cyber Command’s Cyber National Mission Force, the Australian Signals Directorate, the Canadian Centre for Cyber Security and New Zealand’s NCSC [10]. Its wording is “almost certainly subordinate to the Russian Federal Security Service (FSB) Centre 18” [8], and Canada’s Communications Security Establishment repeated that formulation [11]. The advisory also records the aliases a reader will meet in other vendors’ reporting: SEABORGIUM, Callisto Group, TA446, COLDRIVER, TAG-53 and BlueCharlie [8].

The distinction is worth keeping. A probabilistic government assessment restated without its qualifier in a vendor blog, then again without its source in a news summary, is how confidence levels quietly become facts.

Where the 2024 disruption fits

In October 2024, Microsoft’s Digital Crimes Unit and the US Department of Justice seized over one hundred domains between them, with Microsoft accounting for 66 and the department for 41, against infrastructure used to target elected officials, think tanks, journalists and public sector staff [9]. Microsoft’s reasoning at the time was explicitly attritional: “Rebuilding infrastructure takes time, absorbs resources, and costs money” [9]. The same action recorded 82 customers targeted since January 2023, at roughly one attack per week [9].

Two years on, the same actor runs thirteen campaigns in eight months, sends from other people’s websites, and reaches more than a hundred organisations. The reading is not that seizure failed, but that raising the cost of dedicated infrastructure pushes an operator toward infrastructure it does not own. Compromised hosting is the predictable destination, and it is harder to take down because somebody legitimate stands behind it.

What to monitor

  • Archive extraction followed by execution of a virtual hard disk image or a shortcut file, then an installer, then a new scheduled task, in a short window on one host [1][5].
  • Scheduled tasks with plausible system-sounding names created outside your build and management tooling, including the three Microsoft names [1][6].
  • WebDAV being enabled on an endpoint that has no business need for it [5][6].
  • Mail from established, previously unseen third-party domains carrying password-protected archives, with the password supplied as an image [1][7].
  • Your own externally hosted websites: who can create accounts on them, whether outbound mail from them is monitored, and whether they are in the asset inventory at all [1].
  • Phishing-resistant authentication for the staff groups this actor historically pursues, since mailbox access and forwarding rules remain the end objective [8][11].

Nothing in the chain is novel in isolation: archives, shortcut files, installers, scheduled tasks and a scripted backdoor are all well-trodden. The change on the record is organisational: an espionage service that previously spent its effort researching individuals is now spending it on reach, and getting the conversion rate it needs by taking work away from the victim. Planning assumptions built on the older profile should be revisited on that basis rather than on the malware names.

Sources

Every R3KONX article cites its primary material. 11 sources, in order of first citation. Links open the original publication.

  1. Star Blizzard refines phishing and malware delivery with the RedFlick technique Microsoft Threat Intelligence · 2026-09-29
  2. Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond CyberScoop · 2026-09-29
  3. Russian state hackers use new RedFlick technique to push malware BleepingComputer · 2026-09-30
  4. Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net Dark Reading · 2026-09-30
  5. Star Blizzard scales phishing operations with RedFlick malware delivery Field Effect · 2026-09-30
  6. New Windows Malware Attack Uses Scheduled Tasks to Deploy CosmicPulse Backdoor eSecurity Planet · 2026-10-01
  7. Cyber News Roundup, 2 October 2026 Integrity360 · 2026-10-02
  8. Advisory: Russian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns UK NCSC with CISA, FBI, NSA, CNMF, ASD's ACSC, CCCS and NCSC-NZ · 2023-12-07
  9. Microsoft and US Government Disrupt Russian Star Blizzard Operations Infosecurity Magazine · 2024-10-04
  10. US, Allies Highlight Russian-State Cyber Actor Star Blizzard Spear-phishing Campaigns U.S. Cyber Command · 2023-12-07
  11. Joint cyber security advisory warns of spear-phishing campaigns against targets of interest worldwide Communications Security Establishment Canada · 2023-12-07

Researched and written by the R3KONX analysis desk from the cited primary material. Counts, dates and technical description are Microsoft's as published on 29 September and corroborated against independent reporting of the same research; no indicators are reproduced here, and the attribution quoted is CISA's as Microsoft states it rather than an R3KONX assessment. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.