Star Blizzard hits 100+ orgs with RedFlick, CosmicPulse backdoor
Microsoft ties 13 phishing campaigns since January to Russia's Star Blizzard, using a new RedFlick delivery technique to drop the CosmicPulse backdoor at 100+ US/UK orgs.
Microsoft says the Russian state actor it tracks as Star Blizzard has refined its tradecraft with a new malware-delivery technique — RedFlick — and used it across at least 13 large-scale phishing campaigns since January 2026, hitting more than 100 organizations primarily in the US and UK. The details are in Microsoft Threat Intelligence's September 29 writeup.
Microsoft attributes Star Blizzard to Russia's FSB (Center 18). The group is also tracked as SEABORGIUM, Callisto, TA446, and COLDRIVER. This is credential-theft-and-espionage tradecraft, not a smash-and-grab — the target list runs to NGOs, Western think tanks, governments, and organizations tied to Ukraine policy.
What RedFlick does
RedFlick is the evasion wrinkle. Per Microsoft, the chain requires only a single user interaction, then initiates a set of scheduled tasks that deploy Star Blizzard's custom backdoor, CosmicPulse (a Python-based implant). Lures impersonate the target's own organization or well-known institutions — Microsoft cites invitations themed around think tanks and Ukrainian authorities, plus tax-audit, payment, and fine notices seen earlier in the year.
Delivery infrastructure leans on compromised legitimate accounts: Microsoft notes Star Blizzard has abused hijacked WordPress and cPanel email accounts to distribute campaign messages, which blunts reputation-based filtering.
Attribution
Microsoft attributes the activity to Star Blizzard/FSB directly; treat that as vendor attribution, not a court finding. CyberScoop's reporting corroborates the RedFlick and CosmicPulse naming and the 100+ organization figure. The targeting expanded from Ukraine-linked entities early in the year to broader Western policy organizations by spring — Microsoft's read is that the Ukraine operations doubled as a proving ground for new capabilities.
Indicators of compromise
Microsoft's blog carries the full indicator set. Among the network indicators reported:
# Reported by Microsoft Threat Intelligence, 2026-09-29
secure-dns-hub[.]com # campaign infrastructure
103.160.59[.]97 # associated IP
Pull the primary writeup before building rules — Microsoft publishes the complete IOC list and hunting queries there; the two above are a starting point, not the full package.
Action checklist
- Hunt for scheduled tasks you did not create. RedFlick's tell is task creation following a single click-through. Review recently added scheduled tasks on endpoints belonging to policy, research, and executive staff.
- Block the reported infrastructure at DNS and proxy, then pull Microsoft's full IOC set and load it into EDR.
- Prioritize the target profile. If your org works on Ukraine policy, sits in a think tank/NGO, or advises government, assume you are in scope and brief high-risk users on the impersonation lures.
- Harden inbound mail from compromised-but-legitimate senders. Reputation alone will not catch messages sent from hijacked WordPress/cPanel accounts — lean on content and behavioral detection.
- Enforce phishing-resistant MFA (FIDO2) on the accounts these operators are after.
Context
Star Blizzard is a repeat character. Microsoft's 2023 writeup documented the same actor tightening evasion; RedFlick is the latest iteration on a years-long credential-phishing operation. The pattern that matters for defenders: each cycle moves further from link-only phishing toward malware delivery on top of the compromise, and each leans harder on legitimate, hijacked infrastructure to stay under reputation filters.