Star Blizzard RedFlick Phishing: What IT Teams Need to Know
Summary
Microsoft reports that Star Blizzard has shifted to larger-scale phishing campaigns and a new malware delivery technique called RedFlick. The change lowers the number of steps needed to infect victims with the CosmicPulse backdoor, increasing risk for governments, NGOs, think tanks, and organizations linked to support for Ukraine.
Star Blizzard RedFlick phishing: what changed
Microsoft Threat Intelligence says the Russian state actor Star Blizzard has updated its tradecraft in 2026 with a new malware delivery technique called RedFlick. This matters because the new approach reduces user friction, improves evasion, and supports larger phishing campaigns aimed at high-value organizations.
What’s new
Shift from targeted spear phishing to larger campaigns
Star Blizzard has moved beyond smaller, highly targeted lures and is now sending phishing waves at a much larger scale. Microsoft observed campaigns ranging from tens to hundreds of emails, suggesting the actor is using mass-mailing infrastructure to expand its reach.
RedFlick simplifies malware delivery
Previously, Star Blizzard often relied on more complex infection chains. With RedFlick, the attacker only needs a single user interaction to start the compromise process. The technique uses scheduled tasks to deploy CosmicPulse, the group’s custom backdoor/downloader.
Use of compromised websites and accounts
Microsoft also observed the actor using accounts created on compromised websites to send phishing emails, adding another layer of detection evasion and helping phishing messages appear more credible.
Who is being targeted
According to Microsoft, the campaigns primarily target:
- Ukrainian individuals and institutions
- International NGOs
- Western think tanks
- Government organizations
- Financial institutions and policy groups tied to support for Ukraine
Microsoft says more than 100 organizations were affected, mainly in the United States and United Kingdom.
Why this matters for IT administrators
For security teams, the key concern is that RedFlick lowers the barrier to successful compromise. Fewer steps for the user means fewer chances for the attack chain to fail. Combined with larger phishing volumes, this can increase both exposure and incident response workload.
Administrators should also note that password-protected archives and follow-up email threads remain part of the delivery process, which can bypass simple content inspection if controls are not tuned properly.
Recommended next steps
- Review Microsoft Defender detections and hunting guidance from the advisory
- Block or closely inspect password-protected ZIP and RAR attachments from untrusted senders
- Monitor for suspicious scheduled task creation on endpoints
- Hunt for signs of CosmicPulse-related activity and follow published IOCs
- Reinforce phishing awareness for users handling policy, diplomatic, NGO, or Ukraine-related communications
- Ensure high-risk users have strong protections such as MFA, conditional access, and enhanced email security
Bottom line
Star Blizzard’s adoption of RedFlick marks a meaningful evolution in phishing and malware delivery. Organizations in government, research, nonprofit, and financial sectors should treat this as a priority threat and use Microsoft’s detections, IOCs, and hunting queries to strengthen defenses.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies