Star Blizzard scales up phishing against Ukraine backers
Star Blizzard, a Russian state-backed hacking group, has moved from small, carefully targeted phishing operations to much larger campaigns in 2026, according to a new report from Microsoft. The group has also added a new malware delivery method that needs only one click from the victim.
Microsoft said the activity has hit more than 100 organizations, most of them in the U.S. and UK. Targets include Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments and financial institutions that back Ukraine politically or financially.
Star Blizzard is also tracked as Callisto and ColdRiver. Western governments have previously tied it to Russia's Federal Security Service (FSB), the country's main domestic security and intelligence agency. The group has been active since at least 2017 and has a history of going after government agencies, NGOs and organizations working in international affairs.
From spear-phishing to mass mailing
The group was known for highly targeted spear-phishing. Since the start of 2026, Microsoft researchers have seen it send tens or hundreds of emails in a single campaign.
Researchers believe the change likely comes from Star Blizzard adopting a mass-mailing phishing platform. Such a platform lets the group automate its attacks and reach more potential victims. Microsoft has counted at least 13 large-scale campaigns since January.
The way the group sends its emails has changed too. Since March, the hackers have been contacting targets from accounts created on compromised websites. Before that, they tended to register accounts with free email services and pose as people the victims would recognize, such as political figures, academics or former diplomats.
Ukraine first, then the rest of the world
The first campaigns, spotted in January and February, focused on users of Ukr.net, a Ukrainian email provider. The attackers posed as Ukrainian authorities and told recipients they faced a tax audit or owed an unpaid fine.
From March, the group widened its scope beyond Ukraine. Many of the lures were fake invitations to conferences or events that appeared to come from well-known think tanks or NGOs. In some cases, the hackers went after several employees at the same organization and made the phishing emails look like internal messages.
"The actor's shift from Ukraine-focused operations to global targets could indicate Star Blizzard initially targeted Ukraine to test their new capabilities," Microsoft said.
RedFlick replaces a multi-step infection chain
Along with the larger campaigns, Star Blizzard has adopted a new malware delivery technique that Microsoft calls RedFlick.
The attack usually starts with an initial phishing email. If the victim replies, the group follows up with a password-protected archive. When the victim opens a file inside that archive, RedFlick runs. It uses scheduled tasks on the victim's computer to install CosmicPulse, the group's backdoor, and makes the activity harder to spot.
The key difference is the effort required from the target. RedFlick needs just one action. The group's earlier method relied on ClickFix, a social engineering technique that has also shown up in other recent malware campaigns, and it required victims to complete several steps before CosmicPulse was installed.
"Combined with the actor's shift toward large-scale phishing operations during the same period, these changes likely improve Star Blizzard's ability to reach more targets, evade detection, and increase the likelihood of successful compromise," Microsoft said.
Why It Matters
For organizations that work on Ukraine-related policy, funding or research, this report changes the risk picture. A group that used to pick a handful of high-value individuals now appears able to send phishing waves to many people at once. Being a less prominent staff member at a think tank or NGO no longer means being out of reach.
Two details stand out. Using compromised websites instead of free email services could make sender reputation checks less useful. Fake internal messages and conference invitations also show that the group still puts effort into credible lures while working at scale. The drop from a multi-step ClickFix chain to a single action suggests the group is removing friction wherever it can.
This comes against a wider backdrop of Russian pressure on Ukraine's digital space, including strikes on data centers in Kyiv. It is worth watching whether Star Blizzard's global targeting grows further and whether other state-backed groups adopt similar mass-mailing tools. Defenders should treat unexpected password-protected archives and event invitations with extra caution, even when they appear to come from inside their own organization.
