Skip to content
Back to Guavy Wire
Stocks

Russian Hackers Expand Global Reach with New Malware Tactics

Instruments
MSFT
Share

A Russian government-backed hacking group known as Star Blizzard has expanded its operations to target governments, think tanks, and non-profits around the world, with a focus on Ukraine. According to Microsoft research published Tuesday, the group has shifted from exclusive spear-phishing operations to larger-scale phishing campaigns, using novel malware called RedFlick.

The company observed that Star Blizzard's new approach allows for greater efficiency in compromising victims, as it requires only a single user interaction to gain access. The group's tactics have been effective, with at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide since January 2026.

RedFlick has proven to be a key adaptation for the group, allowing them to evade detection by initiating scheduled tasks to deploy their custom backdoor, CosmicPulse. This marks a significant shift in Star Blizzard's tactics, as they initially focused on Ukraine before expanding globally.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc