"In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns," Microsoft wrote — a concise description that captures both a tactical shift and a widening aim.
Microsoft on Star Blizzard's new approach
According to Microsoft research published Tuesday and summarized by CyberScoop, Star Blizzard — an actor Microsoft links to the Russian Federal Security Service (FSB) — has altered its tradecraft in 2026. The change moves the group from tightly targeted spear-phishing toward "larger-scale phishing operations" that run at a scale "not previously seen from the actor," Microsoft said. Those larger campaigns run from tens to hundreds of email messages each and appear to be automated through a mass-mailing phishing platform to expand the initial targeting pool.
RedFlick and CosmicPulse: how the infection flow works
Microsoft identified a novel malware delivery technique called RedFlick. The company described RedFlick as effective not only because of volume but because its "infection flow only requires a single user interaction, reducing friction in the compromise process." RedFlick launches scheduled tasks that ultimately deploy the actor’s custom backdoor, CosmicPulse — a chained technique Microsoft characterized as helping to evade detection.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleScale, lures, and target set
Since January 2026 Microsoft observed at least 13 distinct large-scale phishing campaigns carried out by Star Blizzard. The most common lures invite recipients to exclusive events, but campaigns also used messages about tax audits, payment notices and fines. Early campaigns focused on Ukrainian targets; by spring 2026 the actor expanded beyond Ukraine to pursue NGOs, think tanks, governments and financial institutions worldwide. Microsoft said the campaigns have targeted Ukrainians as well as financial institutions and governments that have supported Ukraine, and that activity has affected over 100 organizations, primarily in the United States or United Kingdom.
Previous actions, takedowns, and naming
Microsoft noted this shift builds on earlier observations of the same actor, with prior reporting in 2023 and 2025 and takedown efforts conducted in 2024. The actor has been known to the security community under several aliases, including SEABORGIUM, Callisto Group, TA446 and COLDRIVER, Microsoft wrote.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams — The single-interaction infection flow and the use of scheduled tasks to stage CosmicPulse increase the importance of detecting post-click activity and scheduled-task creation. Microsoft’s description implies detection logic should include automated mass-phishing indicators and artifacts tied to scheduled-task deployment.
- Policymakers and regulators — The actor’s stated focus on governments and entities that supported Ukraine, and the geographic concentration of observed compromises in the United States and United Kingdom, may inform cross-border incident response coordination and public guidance on phishing campaigns tied to nation-state activity.
- Affected enterprises and procurement leaders — Organizations that host events, process financial notices, or are engaged in Ukraine-related policy work should be aware that those themes were used as lures. Microsoft’s finding that attacks expanded from focused testing in Ukraine to broader global targeting suggests care in handling event invitations and documents originating outside normal partner channels.
Microsoft’s reporting frames RedFlick as an operational adaptation: a mass-mailing capability to widen the pool of potential victims combined with a delivery chain that minimizes user steps to infection and leverages scheduled tasks to bring in the CosmicPulse backdoor. That mix — volume plus a low-friction infection flow — is the specific operational change Microsoft flagged in 2026.
The record Microsoft provides leaves one concrete point to watch: whether the group maintains this mass-mailing posture or integrates RedFlick and CosmicPulse into further refinements. For now, the observable facts are clear — a shift in scale, a reuse of event- and finance-themed lures, and more than 100 affected organizations concentrated in the U.S. and U.K. — and they come straight from Microsoft’s analysis.
Read the original Microsoft-based reporting at CyberScoop: https://cyberscoop.com/microsoft-star-blizzard-redflick-phishing-campaigns/




