Microsoft Threat Intelligence says the Russian state actor Star Blizzard has changed how it phishes in 2026. In its September 29 report, Microsoft describes at least 13 distinct large-scale phishing campaigns since January, aimed mainly at NGOs, think tanks and government organizations. The company says the RedFlick campaigns it tracked affected over 100 organizations, primarily in the United States and the United Kingdom.
Microsoft notes that CISA attributes Star Blizzard to Russia’s FSB Centre 18. The shift is in volume and delivery. Where the group once ran targeted spear phishing, the 2026 campaigns ranged from tens to hundreds of emails each. Since March, the actor has also sent mail from accounts it created on compromised websites hosted on cPanel and WordPress, which Microsoft assesses with high confidence the group had compromised for this purpose. The malware delivery technique Microsoft calls RedFlick starts scheduled tasks that install the actor’s CosmicPulse backdoor. Microsoft says it needs only one user interaction, where the earlier ClickFix chain asked victims to complete several steps.
The lures were event invitations and finance notices. Microsoft’s pattern for the initial contact is an email without an attachment, then a follow-up with a password-protected archive once the target replies. It also flags a sender-address tell: the real person’s organization appears in the username part of the address rather than in the domain.
Microsoft’s recommended defenses are phishing-resistant authentication methods, Conditional Access policies, Safe Links and Safe Attachments, and endpoint detection and response in block mode.
Why it matters: a group that ran hand-crafted lures can now send in bulk, and the lure still depends on a reply. That puts the control in the mail flow, where a rule on the sender-address pattern is cheap to test, and in how staff treat unsolicited invitations. Our coverage of Britain’s passkey rollout explains why phishing-resistant sign-in blunts the credential-theft side. North Korea’s fake-job scheme uses the same reply-first approach.