Adversary Intelligence — 2026-10-01

FSB-Linked Star Blizzard Shifts to Mass Phishing Campaigns Targeting Over 100 Organizations Supporting Ukraine

BLUFStar Blizzard's pivot to mass phishing with a single-action infection chain forces every Western policy and civil-society organization supporting Ukraine to treat external event invitations as potential FSB operations.

Microsoft reported on September 29 that Star Blizzard, which CISA attributes to FSB Centre 18, has run at least 13 large-scale phishing campaigns since January, each sending tens to hundreds of emails, and that the activity has affected more than 100 organizations, primarily in the United States and United Kingdom 12. Early campaigns hit Ukr.net users with tax-audit and fine lures; from March, lures became fake think-tank and NGO event invitations sent from accounts on compromised websites 13. Respondents received a password-protected archive that starts the RedFlick scheduled-task chain, which installs the CosmicPulse backdoor after one user action, replacing the multi-step ClickFix method 13. The Hacker News said at least one computer was infected, but the available text cuts off before any breach count 4.

Analysis
Star Blizzard's shift to mass phishing changes the defender's task from protecting a short list of named individuals to screening inbound event invitations across whole policy, think-tank and financial-sector organizations. A one-action infection chain and sender accounts on compromised websites, not free mail services, weaken reputation-based filtering. The more than 100 affected organizations measure exposure, not compromise, and no breach figure exists, so we cannot judge how many campaigns became intrusions. All reporting traces to one Microsoft publication, so outlet agreement is not independent confirmation. The volume may instead be a trial of new tooling, with the Ukraine-first sequence marking that phase, while real collection comes from a few selected high-value victims.
4 sources
  1. Star Blizzard refines phishing and malware delivery with the RedFlick technique - Microsoft Security Blog
  2. Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond - CyberScoop
  3. Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters - The Record (Recorded Future News)
  4. Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE