MICROSOFT Threat Intelligence attributes the campaigns to Star Blizzard (also known as COLDRIVER, SEABORGIUM), a Russian state-linked group tied to FSB Centre 18. Since January 2026, the group has shifted from one‑to‑one spear phishing to mass mailings, delivering phishing emails to think tanks, NGOs, governments, and financial institutions that support Ukraine. Microsoft tallies more than 100 affected organisations and 13+ campaigns, with the bulk of activity observed in the US and UK.
The RedFlick technique delivers using hijacked websites as mail senders. After a target replies to a password‑protected ZIP or RAR file (the password arrives as an image to better evade scans), a shortcut file disguised as a PDF is opened, which then installs an MSI package.
By April, the MSI setup created three scheduled tasks: one exfiltrates the computer and user name; another configures WebDAV so Windows can fetch remote files over HTTP; the third runs a CosmicPulse downloader masquerading as a Control Panel applet. This enables a Python‑based backdoor on the victim machine. In July, a PDF‑hiding shortcut added an encoded command to fetch a fresh MSI installer, and by mid‑August a campaign used steganography to conceal identifiers. One March campaign also involved a separate iOS backdoor, DarkSword.
Impact includes diplomats, researchers, journalists, parliament staff and Ukrainian‑aid financial groups; even Kyiv hotels reportedly received fake notices. The practical response emphasises monitoring for unexpected event invitations, blocking outside password‑protected archives, spotting new scheduled tasks invoking control[.]exe or WebDAV, and using phishing‑resistant MFA for sensitive roles.