Microsoft says the Russian state threat actor it tracks as Star Blizzard has expanded its operational playbook with large-scale phishing, compromised-website accounts, and a malware-delivery technique it calls RedFlick. Microsoft reported the activity on September 29 and said it has observed the changes since January 2026.
According to Microsoft, RedFlick uses scheduled tasks to help deploy the actor’s CosmicPulse backdoor after a single user interaction. That represents a change from earlier ClickFix-style infection chains that required more victim actions. Microsoft said the campaigns have targeted Ukrainian individuals and institutions as well as NGOs, think tanks, governments, financial institutions, and organizations connected to support for Ukraine.
Defenders should use Microsoft’s published indicators, detections, and hunting guidance to review email telemetry, scheduled-task creation, suspicious attachments, and post-phishing execution. Organizations should also reinforce phishing-resistant authentication, reduce unnecessary script execution paths, and ensure suspicious activity has a defined escalation route. The reported move toward larger-scale mailing increases the value of monitoring for campaign-wide patterns rather than evaluating messages only one at a time.
