Skip to content
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond

Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond

Cyberscoop •Tim Starks • September 29, 2026

A group of Russian government hackers is refining its attacks to make it easier to eavesdrop on victims and significantly expand its targets among governments, think tanks and nonprofits around the world, with an emphasis on Ukraine, Microsoft research published Tuesday concludes.

The company examined a change in the approach of a group it calls Star Blizzard, which is affiliated with the Russian Federal Security Service (FSB), and its novel malware, RedFlick.

“In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns,” Microsoft wrote in a blog post . “The larger-scale phishing operations were observed at a scale not previously seen from the actor, ranging from tens to hundreds of email messages per campaign. This change likely reflects the actor’s adoption of a mass-mailing phishing platform to automate campaign execution and increase the likelihood of successful compromises by significantly expanding the initial targeting pool.”

Microsoft said the RedFlick campaigns have targeted Ukrainians, as well as financial institutions and governments that have supported Ukraine. It said it has seen the activity affect over 100 organizations that are primarily in the United States or United Kingdom.

One of the things that makes RedFlick effective isn’t just its pure volume, but the fact that its “infection flow only requires a single user interaction, reducing friction in the compromise process,” the company said in its blog post.

The most common phishing lure is inviting potential victims to exclusive events, but it also solicits its targets with information supposed tax audits, payment notices and fines.

“Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide,” the company wrote.

The initial targets were in Ukraine but by spring it was going after those outside the nation it invaded in 2022. “The actor’s shift from Ukraine-focused operations to global targets could indicate Star Blizzard initially targeted Ukraine to test their new capabilities,” Microsoft wrote.

RedFlick has been a key adaptation as “a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor’s custom backdoor, CosmicPulse,” the company said.

This isn’t the first time that Microsoft has called out Star Blizzard, with past observations coming in 2023 and 2025 and takedown efforts coming in 2024 .

Star Blizzard has been known by other names as well: SEABORGIUM, Callisto Group, TA446 and COLDRIVER .

What the Section 702 lapse means for cybersecurity

Jailbreaks, sandboxes, and the limits of AI safeguards

ClickFix and the social engineering of routine

AI-adaptable security platforms are critical for autonomous decision-making

US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says

As AI world debates security, NVIDIA releases open source tools for agents

ShinyHunters trades financial extortion for a reckless war of ego with the FBI

Supreme Court permits states to use SAVE database for citizenship checks

New bill would create federal investigative body for AI-driven hacks

CISA outlines improvement plan for CVE program

Researchers use AI to find widespread software decoder flaw

The AI hacking apocalypse is not inevitable

Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings

Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

House and Senate members propose legislation for CISA to step up cyber defenses for biotech

The president has called for AI leadership. Here’s the mission.

After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program

Dems seek top-to-bottom assessment of CISA workforce

Extracted Entities