Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 01, 2026 · 10 min read

Star Blizzard's RedFlick Phishing Hits 100+ Organizations

Microsoft's September 29, 2026 report says the FSB group also tracked as Callisto and ColdRiver has run at least 13 large phishing campaigns since January, most dressed as closed door event invitations, and now needs one click to install its CosmicPulse backdoor.

The email asks whether you would join a private roundtable on European security, hosted by a think tank you know. Nothing is attached, so there is nothing for a mail filter to catch. Reply, and a second message brings the invitation inside a password protected archive. For reporters and NGO staff who work on Ukraine, messages like this are routine, and Russia's Star Blizzard has spent 2026 exploiting that. Microsoft's September 29 report describes the Star Blizzard RedFlick campaigns in detail: one opened file is enough to plant a backdoor.

Key Takeaways

  • Microsoft reported on September 29, 2026 that Star Blizzard has run at least 13 large scale phishing campaigns since January, affecting over 100 organizations primarily in the United States and United Kingdom.
  • RedFlick is Microsoft's name for a delivery technique that uses scheduled tasks to deploy the CosmicPulse backdoor after a single user interaction, replacing multi step ClickFix chains.
  • Nine of the 13 subject lines Microsoft published are event invitations, five of them billed as closed or closed door, borrowing names such as IISS and Chatham House.
  • Since March 2026, Star Blizzard has sent its bulk phishing from accounts created on compromised cPanel and WordPress websites.
  • CISA, the UK's NCSC and six partner agencies assessed in December 2023 that Star Blizzard is almost certainly subordinate to FSB Centre 18.

Who Is Star Blizzard?

Star Blizzard is a Russian state hacking group that the UK's NCSC, CISA and six partner agencies assess is "almost certainly subordinate to the Russian Federal Security Service (FSB) Centre 18." Their joint advisory of December 7, 2023 lists its other names: SEABORGIUM, Callisto Group, TA446, COLDRIVER, TAG-53 and BlueCharlie. Since 2019, the advisory says, it has targeted academia, defense, governmental organizations, NGOs, think tanks and politicians. The Record dates its activity to at least 2017.

Journalists have been on the list for years. Citizen Lab's Rivers of Phish report, published with Access Now on August 14, 2024, recalls that F-Secure described the Callisto group in 2017 as phishing "military personnel, government officials, think tanks and journalists." Citizen Lab's own cases included Polina Machold, publisher of the investigative outlet Proekt, and former US ambassador to Ukraine Steven Pifer, each approached by someone posing as a person they knew. Two days later, Proofpoint showed China-aligned TA419 using the same reply first approach with fake AI policy committee invitations.

Microsoft said in January 2025 that it and the US Department of Justice had seized or taken down more than 180 of the group's websites since October 3, 2024, and that the hackers "swiftly transitioned to new domains." A caution on names: Secret Blizzard, better known as Turla, sits in a different FSB center, and Forest Blizzard is the GRU's APT28. Neither is this group.

How Did Star Blizzard's Phishing Change in 2026?

It went from handpicked targets to bulk mail. Microsoft observed the group shift "from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns," sending "tens to hundreds of email messages per campaign." The company says the change "likely reflects the actor's adoption of a mass-mailing phishing platform." The subject lines it published show the progression:

  • January and February: Ukrainian language notices about a tax audit and an unpaid fine, impersonating Ukrainian authorities and sent to Ukr.net users with the malicious archive attached.
  • March: "Invitation to an IISS [Private Roundtable/Closed-Door Discussion] on European Security," aimed at government officials, security researchers, academia, media and NGOs, plus a CES roundtable for technology companies and an "Atlantic Council Closed-Door Strategic Discussion."
  • April to June: a capital allocation session for financial organizations, a "Future of Peace Operations Forum" for diplomatic bodies, and "Invitation to the Chatham House London Conference 2026 – 9 July 2026."
  • July and August: a USUBC roundtable aimed at Ukrainian civil society, a water shutoff notice sent to Kyiv hotels, and a "Payment Advice Note" for staff at an international financial organization.

Nine of the 13 subject lines are event invitations, and five of those bill the event as closed or closed door. Twelve led to RedFlick. The thirteenth, the Atlantic Council lure, sent respondents a link to install the DarkSword iOS backdoor instead. Microsoft does not say any of the named institutions were breached; their names were borrowed.

The sending side changed in March. Star Blizzard used to impersonate someone the target knew from free accounts, predominantly Protonmail and Microsoft consumer addresses. For bulk campaigns it now creates accounts on websites hosted on cPanel and WordPress, and "Microsoft Threat Intelligence assesses with high confidence that these websites have been compromised by Star Blizzard for this purpose." It also writes to several people inside one organization, with messages made to look like internal mail.

What Is RedFlick, Step by Step?

RedFlick is Microsoft's name for a malware delivery technique that "helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse." It replaces the group's ClickFix chains, which made victims complete several actions, with a flow that "only requires a single user interaction." As Microsoft describes it:

  1. First contact. An email, usually without an attachment, proposes the event.
  2. The follow up. Once the recipient responds, a second message brings a password protected RAR or ZIP archive, with the password shown as an image in the email.
  3. The one click. The archive holds an LNK shortcut disguised as a PDF. In January it sat inside a VHDX virtual disk beside a hidden folder containing a BAT script and a real decoy PDF. Opening that shortcut started conhost.exe in a hidden window, showed the decoy, and used SSH.exe with PermitLocalCommand enabled to download and run a remote MSI installer.
  4. Scheduled tasks. The installer created one task in January and three by April: Internet Quality Test Connection, Network Configuration Manager and System Health Monitor. The first sends the computer name and username to the command server and can run an attacker supplied DLL. The second prepares the Windows WebDAV client. The third uses control.exe to pull the next stage.
  5. The downloader. That stage is a Control Panel applet DLL, publicly known as NOROBOT or BAITSWITCH, whose sole purpose is to install CosmicPulse.

In July, Microsoft saw a password protected RAR nested inside a ZIP, with a shortcut that used curl to fetch a PDF from an attacker server and PowerShell to carve a Base64 encoded command out of it. BleepingComputer's writeup reproduces Microsoft's diagrams.

Ukrainian researchers documented an overlapping chain before RedFlick had a name. On June 23, 2026, Digital Security Lab Ukraine described fake Ukraine Recovery Conference invitations sent to civil society groups and journalists: a password protected ZIP, a VHDX, a shortcut, then scheduled tasks. The lab named no actor and could not retrieve the final payload; Microsoft says the techniques overlap. Two of the lab's indicators, 103.160.59[.]97 and secure-dns-hub[.]com, now sit in Microsoft's table as hosts for the CosmicPulse downloader. The lab also explains the virtual disk: files opened from a mounted image lack the mark Windows attaches to internet downloads, so the usual SmartScreen warning never appears.

What Does CosmicPulse Do?

CosmicPulse is "a malicious Python backdoor" that lets Star Blizzard's operators run their own code on an infected Windows computer. Microsoft says its capabilities are unchanged from earlier reporting and equates it with the malware Google calls YESROBOT. Google's October 2025 analysis describes a minimal backdoor that fetches AES encrypted commands over HTTPS from a hardcoded server and "requires all commands to be valid Python," which operators can use to download and run files or retrieve documents.

The downloader fetches two ZIP files, one holding a Python 3.8 64 bit package and a bootstrapper, and writes an encrypted AES key to the registry at HKEY_CURRENT_USER\Software\Classes\.mollis.

Google also wrote that it "observed only two instances of YESROBOT deployment over a two week period in late May" 2025 before the group dropped it, and judged it a stopgap. Sixteen months later, Microsoft describes the same Python payload as the thing RedFlick exists to install, "going through various little changes to circumvent existing signatures." A tool one vendor wrote off is, by another's account, still in service.

Laptop showing an email inbox beside a blank invitation card and a conference lanyard on a dark desk, illustrating Star Blizzard RedFlick phishing that uses fake event invitations

What This Means for Your Inbox

Email is the whole front end of this operation. As Digital Security Lab Ukraine put it, "A message with no payload passes mail scanning cleanly, and the loader only reaches people who have already shown they are engaged." Your reply is the filter the attackers use.

Personal accounts are in scope. The 2023 CISA advisory says Star Blizzard "has predominantly sent spearphishing emails to targets' personal email addresses," and that it may do so to get around the security controls on corporate networks.

Gmail's list of blocked file types includes .lnk, .msi, .cpl and .vhd, even inside archives, and Gmail does not allow "Password-protected archives with archived content." The list does not name .vhdx, and Microsoft's report does not mention Gmail, so we could not verify what Gmail does with a RedFlick archive. A delivered attachment is not a vetted one. Russia is not alone in this approach either: Iran's CHOSEN BRICK operators spend days building trust with journalists before sending a file.

What Should You Do When an Event Invitation Arrives?

Verify it through a channel you already had before you reply, because the reply is what triggers the malicious follow up.

  1. Read the whole address. Microsoft found that sender addresses carry real names, but "the organization is not within the root or registered domain itself but in the username or local part of the email address." If the think tank's name sits before the @ and an unrelated website sits after it, stop.
  2. Check before you answer. Microsoft's advice is to "directly contact the person you think sent the email using a previously established and trusted contact method such as known email address or phone number."
  3. Refuse the archive. A password protected RAR or ZIP with its password pictured in the email is this campaign's signature. If an extracted "PDF" shows as a Shortcut in File Explorer's Type column, or the archive holds a disk image, delete it.
  4. Warn colleagues. Microsoft saw several people in one organization targeted together, so forward the message to whoever handles security.
  5. Harden the account. Microsoft says Star Blizzard still runs Evilginx phishing from Proton addresses. Google's Advanced Protection Program enrolls with a passkey or security key.
  6. If you opened it, get help. Disconnect the computer. Access Now's Digital Security Helpline is free for civil society, runs 24/7 in ten languages, and says it responds within two hours.

Detections and Indicators for Security Teams

The indicator table in Microsoft's report comes with detections and hunting queries:

  • Antivirus names: Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse and Backdoor:Python/CosmicPulse.
  • Hunting queries: conhost.exe launching curl, ssh.exe run with PermitLocalCommand=yes and LocalCommand=cmd.exe, and the three scheduled task names from April.
  • Indicators: 16 domains, six IP addresses and five file hashes, including an archive named Chatham_London_Conference_2026_Invitation.rar.
  • Mitigations: phishing resistant authentication, Safe Links and Safe Attachments, EDR in block mode, Zero-hour auto purge, attack surface reduction rules, and firewall rules that restrict outbound SSH to external networks.

Looking Ahead

Expect the indicators to age fast. Microsoft says Star Blizzard "periodically overhauls their TTPs to avoid detection, often in response to public exposure," and Google watched the group field new malware five days after its LOSTKEYS tool was disclosed in May 2025.

The shape of the approach is harder to swap out: an invitation with nothing attached, then an archive only after you answer. Remember the sequence, not the file names.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.