FSB-Linked Star Blizzard Shifts to Mass Phishing Campaigns Targeting Over 100 Organizations Supporting Ukraine
Microsoft reported on September 29 that Star Blizzard, which CISA attributes to FSB
Star Blizzard's shift to mass phishing changes the defender's task from protecting a short list of named individuals to screening inbound event invitations across whole policy, think-tank and financial-sector organizations. A one-action infection chain and sender accounts on compromised websites, not free mail services, weaken reputation-based filtering. The more than 100 affected organizations measure exposure, not compromise, and no breach figure exists, so we cannot judge how many campaigns became intrusions. All reporting traces to one Microsoft publication, so outlet agreement is not independent confirmation. The volume may instead be a trial of new tooling, with the Ukraine-first sequence marking that phase, while real collection comes from a few selected high-value victims.
4 sources
- Star Blizzard refines phishing and malware delivery with the RedFlick technique -
Microsoft Security Blog - Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond -
CyberScoop - Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters -
The Record (Recorded Future News) - Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor -
The Hacker News