Star Blizzard, the Russian espionage group better known for slow, hand-crafted phishing of diplomats and think tank staff, has started sending its lures in bulk. Microsoft Threat Intelligence reports that since January 2026 the group has run at least 13 distinct large-scale campaigns, affecting more than 100 organizations, mainly in the United States and United Kingdom, and has swapped its old multi-step infection chain for one that needs a single user action.
That matters because Star Blizzard's targets are exactly the people who set Western policy on Ukraine. Microsoft lists Ukrainian individuals and institutions, international NGOs, think tanks, governments and financial institutions that have supported Ukraine politically or financially. CISA attributes the group, also tracked as COLDRIVER and Callisto, to Centre 18 of Russia's Federal Security Service (FSB).
From a handful of emails to hundreds
In earlier years the actor typically struck up a conversation with one target at a time, often impersonating a known political or diplomatic figure, before sending anything malicious. In 2026 Microsoft saw campaigns of tens to hundreds of messages each, which it says likely reflects the adoption of a mass-mailing platform. The first waves, in January and February, hit users of the Ukrainian mail provider Ukr.net with fake tax audit and fine notices. From March the lures went global: invitations to closed-door roundtables purportedly hosted by the IISS, the Atlantic Council, Chatham House and USUBC, a fake forum on peace operations, and in August a bogus payment advice note sent to staff at an international financial organization. Kyiv hotels received a notice about a water shutdown.
The senders changed too. Instead of Proton or Microsoft consumer accounts, the group now sends from accounts it created on compromised cPanel and WordPress websites, reusing the same account name across domains. Microsoft assesses with high confidence that Star Blizzard compromised those sites itself.
One click instead of a ClickFix routine
Anyone who replies to the opening email gets a password-protected ZIP or RAR, with the password sent as an image. Microsoft tracks what happens next as RedFlick. Where the group's previous ClickFix chains needed victims to complete several steps, RedFlick needs one interaction. In January the archive held a virtual hard disk file carrying a shortcut disguised as a PDF, which ran a hidden script, opened a decoy document and pulled down an MSI installer. That installer created scheduled tasks using control.exe to fetch a downloader dressed up as a Control Panel applet.
By April the installer was creating three scheduled tasks posing as network components, named Internet Quality Test Connection, Network Configuration Manager and System Health Monitor, which beacon the host and user name to the operators and fetch payloads over WebDAV. In July a new chain hid a Base64 command inside a downloaded PDF. The end goal is always CosmicPulse, a Python backdoor (the downloader is also known as NOROBOT or BAITSWITCH, the backdoor as YESROBOT). One March campaign instead pushed a link to the DarkSword iOS backdoor, a tool we covered in an earlier story about a fake iPhone preorder page.
Check the sender's domain, then call them
Microsoft's key tell for defenders: the sender name carries a real person and organization, but the organization appears in the username rather than in the registered domain. If an unexpected event invitation arrives, confirm it through a contact channel you already trust. Microsoft also recommends phishing-resistant authentication, Conditional Access policies and attachment scanning, and says it has notified targeted customers directly. Organizations in the target set should hunt for scheduled tasks with the three names above that invoke control.exe or reach out over WebDAV.
Selected indicators published by Microsoft (defanged):
- 103[.]245[.]231[.]248
- 103[.]245[.]231[.]79
- 2[.]57[.]241[.]246
- 89[.]125[.]209[.]168
- 45[.]84[.]59[.]66
- 103[.]160[.]59[.]97
- SHA-256 9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b
The group's full profile is on our Star Blizzard page. The shift is a trade-off worth noticing: a crew that once relied on patience and precision is now accepting more noise in exchange for reach, which should make it easier to catch and harder to ignore.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.