Russian Hackers Expand Global Reach with New Malware Tactics
A Russian government-backed hacking group known as Star Blizzard has expanded its operations to target governments, think tanks, and non-profits around the world, with a focus on Ukraine. According to Microsoft research published Tuesday, the group has shifted from exclusive spear-phishing operations to larger-scale phishing campaigns, using novel malware called RedFlick.
The company observed that Star Blizzard's new approach allows for greater efficiency in compromising victims, as it requires only a single user interaction to gain access. The group's tactics have been effective, with at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide since January 2026.
RedFlick has proven to be a key adaptation for the group, allowing them to evade detection by initiating scheduled tasks to deploy their custom backdoor, CosmicPulse. This marks a significant shift in Star Blizzard's tactics, as they initially focused on Ukraine before expanding globally.