Microsoft said on September 29, 2026 that it has observed the Russian state threat actor it tracks as Star Blizzard shift to large-scale phishing campaigns and adopt a new malware delivery technique called RedFlick to install its custom backdoor, CosmicPulse. The company said the changes have been under way since January 2026.
What changed
According to Microsoft, Star Blizzard has evolved its detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and the RedFlick delivery technique, which initiates a set of scheduled tasks to deploy the CosmicPulse backdoor.
Microsoft described RedFlick as a departure from the actor's earlier ClickFix-based infection chains, which required victims to complete multiple actions. "By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process," the company wrote.
Microsoft said Star Blizzard is attributed by the United States Cybersecurity and Infrastructure Agency as subordinate to the Russian Federal Security Service Centre (FSB) Centre 18.
Who is affected
Microsoft said the RedFlick campaigns have targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments and financial institutions that have supported Ukraine politically or financially. The company said it has observed the activity affect over 100 organizations, primarily in the United States and United Kingdom.
Since January 2026, Microsoft said it has seen at least 13 distinct large-scale phishing campaigns, ranging from tens to hundreds of email messages each. The earliest, in January and February, targeted unspecified users of the Ukrainian email provider Ukr.net with lures themed as tax audit notices or unpaid fines.
From March, Microsoft said the actor expanded beyond Ukraine using invitations to purported conferences and roundtables, including lures referencing IISS, the Atlantic Council, Chatham House and USUBC events. Microsoft added that the shift from Ukraine-focused operations to global targets could indicate the actor initially tested new capabilities in Ukraine.
Technical details
Microsoft said targets who reply to an initial email typically receive a follow-up message with a password-protected RAR or ZIP archive, with the password included as an image. In mid-January the company observed a malicious Virtual Hard Disk v2 (VHDX) file containing an LNK file disguised as a PDF, a hidden BAT script and a decoy PDF. The BAT file invoked SSH.exe with PermitLocalCommand enabled to download and run a remotely hosted MSI installer.
That MSI, Microsoft said, created a scheduled task using control.exe to fetch a CosmicPulse downloader masquerading as a Control Panel applet. The downloader — also known publicly as NOROBOT or BAITSWITCH — retrieves two ZIP files, writes an encrypted AES key to the HKEY_CURRENT_USERSoftwareClasses.mollis registry key, and uses a Python bootstrapper to decode the CosmicPulse payload, also known as YESROBOT.
By April, Microsoft said the installer created three scheduled tasks masquerading as legitimate network components, named Internet Quality Test Connection, Network Configuration Manager and System Health Monitor, using WebDAV UNC paths to retrieve payloads over HTTP. In July, Microsoft observed a chain in which an LNK file used conhost.exe and curl to download a PDF, from which a PowerShell payload extracted 208 bytes of Base64 data hidden after a cAB magic header.
Microsoft also said Star Blizzard began using accounts on compromised CPanel and WordPress websites to send phishing mail, and that a mid-August campaign employed steganography to conceal identifiers. It noted ProofPoint reported in March that the actor targeted vulnerable Apple iOS devices with the DarkSword backdoor.
What Microsoft says defenders should watch
Microsoft published Defender detection names, advanced hunting queries for Microsoft Defender XDR and Sentinel, and a list of indicators of compromise including file hashes, domains and IP addresses tied to campaigns from January to August 2026.
The company said it directly notifies customers that have been targeted or compromised, and advised organizations in government, NGOs or think tanks adjacent to Ukraine policy to apply its recommended mitigations.
What to do
- Use phishing-resistant authentication methods and lock down account access with Conditional Access policies, Microsoft says; the company also recommends security defaults as a baseline and continuous access evaluation.
- Turn on Safe Links and Safe Attachments in Office 365, configure Defender for Office 365 to recheck links on click, and enable Zero-hour auto purge (ZAP) to retroactively quarantine delivered malicious mail.
- Run endpoint detection and response in block mode, enable Microsoft Defender Antivirus real-time protection, cloud-delivered protection and automatic sample submission, and set investigation and remediation to full automated mode.
- Enable network protection and use browsers that support Microsoft Defender SmartScreen to block malicious and phishing sites.
- Turn on attack surface reduction rules that block executables that do not meet prevalence, age or trusted-list criteria and block execution of potentially obfuscated scripts.
- Use Windows Firewall or an enterprise firewall to prevent or restrict non-essential outbound SSH connections to external or public networks.
- Treat as suspicious an unsolicited first email with no attachment followed by a reply containing a password-protected RAR or ZIP archive, and check whether the organization name appears only in the local part of the sender address rather than the domain; verify via a known phone number or email address.
- Run Microsoft's published hunting queries in Defender XDR and Sentinel for conhost.exe launching curl, SSH invoked with PermitLocalCommand, and the scheduled task names Internet Quality Test Connection, Network Configuration Manager and System Health Monitor, and check the published indicators of compromise.
Key facts and where they come from
- Microsoft says the activity has affected more than 100 organizations, mainly in the US and UK.
Microsoft has observed this activity affect over 100 organizations primarily in the United States and United Kingdom, consistent with Star Blizzard’s longstanding targeting priorities.
- CISA attributes Star Blizzard to Russia's FSB Centre 18, according to Microsoft.
Star Blizzard is attributed by the United States Cybersecurity and Infrastructure Agency (CISA) as subordinate to the Russian Federal Security Service Centre (FSB) Centre 18.
- At least 13 distinct large-scale phishing campaigns observed since January 2026.
Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide.
- RedFlick requires only one user interaction, unlike earlier ClickFix chains.
By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process.
- The CosmicPulse downloader is also tracked publicly as NOROBOT or BAITSWITCH.
The downloader is also known publically as NOROBOT or BAITSWITCH.
- The downloader writes an encrypted AES key to a specific registry key.
It then writes an encrypted AES key to the HKEY_CURRENT_USERSoftwareClasses.mollis registry key.
- By April 2026 the MSI installer created three scheduled tasks posing as network components.
the actor’s MSI installer created three scheduled tasks masquerading as legitimate network components, each with their own purpose
- Phishing mail was sent from accounts created on compromised CPanel and WordPress sites.
In the large-scale campaigns, Star Blizzard has used accounts created on websites hosted on CPanel and WordPress, using the same account name across multiple website domains.
- A mid-August 2026 campaign used steganography to hide identifiers.
a campaign observed in mid-August 2026 employed steganography to conceal identifiers
