Microsoft reported that the Russian state-backed hacking group Star Blizzard expanded its phishing operations in 2026, deploying a new mass-mailing platform and an updated malware delivery method known as RedFlick. The campaign has targeted more than 100 organizations primarily in the United States and the United Kingdom, including Ukrainian entities, international NGOs, think tanks, government agencies, and financial institutions.
Expansion of Mass-Mailing Phishing Campaigns
Active since at least 2017, Star Blizzard—also tracked by threat intelligence researchers as Callisto and ColdRiver—has historically relied on highly targeted spear-phishing attacks. Western governments have previously linked the group to Russia’s Federal Security Service (FSB). Since the beginning of 2026, researchers have observed the actors scaling up their operations by adopting an automated mass-mailing platform that sends batches of tens or hundreds of emails at a time. Microsoft identified at least 13 large-scale campaigns utilizing this infrastructure since January.
The operational shift follows an evolution in how the group sets up accounts to contact targets. While Star Blizzard previously used free email services to impersonate political figures, academics, or diplomats, researchers noted that hackers began utilizing accounts created on compromised websites in March. Early 2026 campaigns focused on users of the Ukrainian email provider Ukr.net, where the group impersonated Ukrainian authorities with messages warning of tax audits or unpaid fines. As the year progressed, targeting broadened globally to include fake invitations to events hosted by reputable think tanks and NGOs.
The RedFlick Malware Delivery Mechanism
Alongside broader distribution, Star Blizzard altered its infection chain through a technique Microsoft named RedFlick. In previous operations, the group used a method called ClickFix, which required victims to complete multiple manual steps before the CosmicPulse backdoor could be installed. Under the updated RedFlick framework, a victim who responds to an initial phishing email receives a password-protected archive. Opening a file inside that archive triggers scheduled tasks on the target computer that silently install the CosmicPulse backdoor.
Microsoft noted that the RedFlick mechanism requires only a single user action, streamlining the compromise process. “Combined with the actor’s shift toward large-scale phishing operations during the same period, these changes likely improve Star Blizzard’s ability to reach more targets, evade detection, and increase the likelihood of successful compromise,” Microsoft stated in its report.
Global Targeting and Intelligence Assessment
The geographic scope of the 2026 campaigns marks a distinct pivot from earlier, localized operations. Organizations targeted globally include financial institutions, government bodies, and political entities involved in foreign policy.

Star Blizzard hacking group and RedFlick malware targets
Who is Star Blizzard?
Star Blizzard is a Russian state-backed hacking group—also known as Callisto and ColdRiver—that Western governments have linked to Russia’s Federal Security Service (FSB).
What is the RedFlick technique?
RedFlick is a malware delivery mechanism used by Star Blizzard that deploys the CosmicPulse backdoor via a password-protected archive, requiring only a single user action to execute.
Which organizations have been targeted?
The group has targeted over 100 organizations, primarily in the U.S. and UK, including Ukrainian entities, international NGOs, think tanks, governments, and financial institutions.
Related reading