Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
A group of Russian government hackers is refining its attacks to make it easier to eavesdrop on victims and significantly expand its targets among governments, think tanks and nonprofits around the world, with an emphasis on Ukraine, Microsoft research published Tuesday concludes.
The company examined a change in the approach of a group it calls Star Blizzard, which is affiliated with the Russian Federal Security Service (FSB), and its novel malware, RedFlick.
“In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns,” Microsoft wrote in a blog post. “The larger-scale phishing operations were observed at a scale not previously seen from the actor, ranging from tens to hundreds of email messages per campaign. This change likely reflects the actor’s adoption of a mass-mailing phishing platform to automate campaign execution and increase the likelihood of successful compromises by significantly expanding the initial targeting pool.”
Microsoft said the RedFlick campaigns have targeted Ukrainians, as well as financial institutions and governments that have supported Ukraine. It said it has seen the activity affect over 100 organizations that are primarily in the United States or United Kingdom.
One of the things that makes RedFlick effective isn’t just its pure volume, but the fact that its “infection flow only requires a single user interaction, reducing friction in the compromise process,” the company said in its blog post.
The most common phishing lure is inviting potential victims to exclusive events, but it also solicits its targets with information about supposed tax audits, payment notices and fines.
“Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide,” the company wrote.
The initial targets were in Ukraine but by spring it was going after those outside the nation it invaded in 2022. “The actor’s shift from Ukraine-focused operations to global targets could indicate Star Blizzard initially targeted Ukraine to test their new capabilities,” Microsoft wrote.
RedFlick has been a key adaptation as “a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor’s custom backdoor, CosmicPulse,” the company said.
This isn’t the first time that Microsoft has called out Star Blizzard, with past observations coming in 2023 and 2025 and takedown efforts coming in 2024.
Star Blizzard has been known by other names as well: SEABORGIUM, Callisto Group, TA446 and COLDRIVER.