ConciseSignal
Following

Russian Star Blizzard hackers expand phishing campaigns worldwide

Russian hacking group Star Blizzard, linked to Russia's FSB, has broadened its cyber attacks from Ukraine-focused spear-phishing to large-scale phishing campaigns globally, according to Microsoft. Using a new method called RedFlick, they have targeted over 100 organizations, mostly in the US and UK, by sending fake event invitations that deliver a Windows backdoor named CosmicPulse. These attacks have primarily affected governments, think tanks, and NGOs since January 2026.

Why it mattersThe shift from targeted attacks to mass phishing increases the risk for a wider range of organizations, including those outside Ukraine. The automation and simplicity of the RedFlick infection process make these campaigns harder to detect and stop.

Sources covering this

The Hacker NewsRussia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor5:20 PM →CyberScoopRussian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond8:01 PM →

In this story

Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity