HackRead

Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique


Microsoft Threat Intelligence has detailed new phishing and malware delivery activity from Star Blizzard, a Russian state threat group. The group, also known as Callisto Group and SEABORGIUM, is associated with Centre 18 of Russia’s Federal Security Service, according to the US Cybersecurity and Infrastructure Security Agency (CISA).

Since January 2026, Microsoft has identified at least 13 large-scale phishing campaigns targeting organizations worldwide. The activity affected more than 100 organizations, primarily in the United States and the United Kingdom.

The targets include Ukrainian individuals, government agencies, NGOs, and think tanks focused on international policy. The newer campaigns use a broader phishing approach, though the group still uses some previously reported techniques.

To send phishing emails at a larger scale, Star Blizzard created accounts on compromised websites running WordPress or cPanel. Microsoft assesses with high confidence that the group compromised these sites for this purpose. The group previously relied mainly on free email services such as Proton Mail and Microsoft consumer accounts.

Star Blizzard also targeted several people within the same organization, sending messages designed to appear as internal communications. Microsoft said the group may have tested its newer techniques against Ukrainian targets before expanding the campaigns internationally.

Phishing email used by Star Blizzard to deliver a password-protected malicious archive. Source: Microsoft

RedFlick Reduces User Interaction

The most notable change is RedFlick, a technique that creates scheduled tasks to help deploy Star Blizzard’s CosmicPulse backdoor. The CosmicPulse downloader is also known as NOROBOT or BAITSWITCH, while the backdoor payload is also called YESROBOT.

Unlike the group’s earlier ClickFix campaigns, which required victims to complete several actions, the newer infection chain can begin with a single user action.

Microsoft researchers noted password-protected ZIP or RAR archives containing files such as Virtual Hard Disk (VHDX) images and shortcut (LNK) files. In one January chain, a VHDX contained an LNK disguised as a PDF, which led to an MSI installer.

The chain also used SSH.exe with PermitLocalCommand to download and execute the MSI. Some campaigns also used conhost.exe, curl and PowerShell to retrieve additional components. In July, the group concealed Base64-encoded PowerShell data inside PDF files.

Star Blizzard’s VHDX infection chain uses a disguised LNK file and SSH.exe to download the CosmicPulse downloader. Source: Microsoft

Scheduled Tasks Aid Persistence

In April, Star Blizzard’s MSI installer created three scheduled tasks disguised as network tasks. One task can send encoded information about the device to a command-and-control server and invoke an attacker-controlled DLL through Control_RunDLL. Another supports WebDAV-based execution, while a third can retrieve and execute the CosmicPulse downloader.

Star Blizzard has used targeted spear-phishing in earlier campaigns, including attacks against civil society organizations. In 2024, Hackread reported on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.

The latest activity highlights Star Blizzard’s use of large-scale phishing alongside less interactive malware delivery and scheduled tasks.

The changes give Star Blizzard a broader phishing reach while reducing the number of steps required to deliver CosmicPulse. Microsoft recommends phishing-resistant authentication, EDR in block mode, and email and endpoint security controls to help organizations detect and block these attacks.





Source link