Microsoft published research showing Star Blizzard, a group tied to Russia's FSB, shifting from exclusively targeted spear-phishing to larger-scale phishing campaigns to reach people and organisations connected to Ukraine, with more than 100 organisations affected since January and victims concentrated in the United States and the United Kingdom. Security agencies in the United States, the United Kingdom, Australia, Canada and New Zealand assess that Star Blizzard almost certainly works under Center 18 of the FSB. The new tooling is a method Microsoft calls RedFlick, which uses Windows scheduled tasks to install a backdoor named CosmicPulse; the lures are fake event invitations naming well-known think tanks and NGOs as hosts, including Chatham House and the Atlantic Council, and many emails are written to appear to come from within the target's own organisation. Since March, the campaign has used email accounts on WordPress and cPanel websites, which Microsoft is highly confident the group compromised for that purpose, replacing the free consumer email services it had used previously. Microsoft says at least one computer was infected but has not disclosed how many organisations were breached. The shift matters because volume campaigns need only a single victim interaction and put far more targets in play than the group's historic tradecraft.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-09-30 |
| Source | CyberScoop |
| Reliability | Tier 2 |