A Russia-linked APT group, known as Star Blizzard (also ColdRiver or Callisto), is widening its phishing operations after a significant disruption two years ago by Microsoft and US officials. In a Microsoft Threat Intelligence blog post published on 29 September 2026, MTI notes that Star Blizzard has replaced its ClickFix approach with RedFlick, a malware-delivery technique that enables speedier compromise of targets.
The actor’s CosmicPulse backdoor (a Python-based payload) is now deployed via RedFlick, which orchestrates a set of scheduled tasks to run the backdoor, reducing the need for extensive victim interaction.
Star Blizzard has historically targeted journalists, NGOs and Russia experts—particularly those supporting Ukraine—and Microsoft reports a shift toward large-scale phishing campaigns since January 2026. The campaigns now involve hundreds of messages per lure and often impersonate tax authorities, financial firms, or think tanks, with phony event invitations and internal communications designed to appear authentic.
Evidence from MTI indicates new infection paths under RedFlick include LNK files within password-protected archives that use conhost[.]exe and cmd[.]exe to trigger an MSI installer and create scheduled tasks. In July, the group demonstrated a chain that hides a PowerShell payload inside a legitimate PDF and uses trusted Windows components to handle execution and persistence, culminating in CosmicPulse delivery with minimal user interaction.
Defence guidance emphasises phishing-resistant authentication, conditional access, anti-phishing tools, EDR in block mode, and Defender SmartScreen to block malicious sites.