Star Blizzard Expands Phishing Attacks with RedFlick Technique
Microsoft Threat Intelligence has uncovered a wave of phishing and malware attacks orchestrated by Star Blizzard, a Russian state-sponsored threat group. Known also as Callisto Group and SEABORGIUM, the group is linked to Centre 18 of Russia’s Federal Security Service, according to the US Cybersecurity and Infrastructure Security Agency (CISA).
Since January 2026, Microsoft identified at least 13 large-scale phishing campaigns targeting over 100 organizations, primarily in the United States and the United Kingdom. The campaigns have affected Ukrainian individuals, government agencies, NGOs, and think tanks focused on international policy. Star Blizzard has expanded its phishing tactics, now using compromised WordPress and cPanel websites to send phishing emails at a larger scale, moving away from free email services like Proton Mail and Microsoft consumer accounts.
One of the group’s most notable techniques is RedFlick, which creates scheduled tasks to deploy the CosmicPulse backdoor, also known as NOROBOT or BAITSWITCH. The infection chain has been simplified, requiring only a single user action to begin. Phishing emails often contain password-protected ZIP or RAR archives with files like Virtual Hard Disk (VHDX) images and shortcut (LNK) files. In one instance, a VHDX contained an LNK disguised as a PDF, leading to an MSI installer.
The scheduled tasks created by the MSI installer help maintain persistence on infected systems. These tasks can send encoded device information to command-and-control servers, execute attacker-controlled DLLs, and retrieve additional malware components. Microsoft recommends phishing-resistant authentication, EDR in block mode, and robust email and endpoint security controls to help organizations detect and block these attacks.