Russian Star Blizzard hackers expand phishing campaigns worldwide
Russian hacking group Star Blizzard, linked to Russia's FSB, has broadened its cyber attacks from Ukraine-focused spear-phishing to large-scale phishing campaigns globally, according to Microsoft. Using a new method called RedFlick, they have targeted over 100 organizations, mostly in the US and UK, by sending fake event invitations that deliver a Windows backdoor named CosmicPulse. These attacks have primarily affected governments, think tanks, and NGOs since January 2026.
- Star Blizzard linked to Russian intelligence agency FSB
- Over 100 organizations targeted since January 2026
- Phishing emails impersonate event invitations from NGOs and think tanks
- RedFlick malware uses scheduled tasks to install CosmicPulse backdoor
- Targets now span beyond Ukraine to US, UK, and other countries
Sources covering this
In this story
More in Cybersecurity
Critical zero-days in Citrix NetScaler exploited, patches released
Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited.
Dutch police arrest former hacker in ShinyHunters probe
Dutch police have arrested Pepijn van der Stap, a previously convicted hacker, in connection with an ongoing investigation into the…
Apple fixes CoreGraphics flaw after targeted attacks
Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly…
New Spectre BTR attack exposes Linux root password hashes
Researchers have unveiled a new Spectre Variant 2 attack, named Branch Target Reuse (BTR), that can extract root password hashes from…