Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Russian FSB‑linked Star Blizzard Expands Mass‑Mail Phishing Campaigns Against Ukraine Supporters and Global Allies

Star Blizzard has moved from targeted spear‑phishing to automated, large‑scale campaigns that use a new RedFlick malware delivery method, affecting over 100 organizations worldwide. The surge highlights the need for robust security‑awareness programs and continuous evidence of control effectiveness for audit readiness.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

Russian FSB‑linked “Star Blizzard” Scales Up Phishing Campaigns Targeting Ukraine Supporters and Global Allies

What Happened – Microsoft reports that the state‑backed group known as Star Blizzard (also called Callisto/ColdRiver) has shifted from highly‑targeted spear‑phishing to mass‑mailing campaigns, launching at least 13 large‑scale operations since January 2026. The group now uses compromised web‑site accounts and a new “RedFlick” delivery method that drops a password‑protected archive; opening the archive installs the CosmicPulse backdoor via scheduled tasks. Over 100 organizations in the U.S., U.K., NGOs, think tanks, governments and financial institutions have been hit.

Why It Matters for Trust & Control Assurance

  • This activity tests the effectiveness of an organization’s security‑awareness program and its ability to detect and block phishing‑derived malware – a core control area for continuous assurance.
  • Automated, high‑volume phishing defeats ad‑hoc training; continuous monitoring of email‑security controls and documented awareness metrics provide defensible evidence for audits.
  • Mapping the incident to a single control objective—people‑centric security awareness and training—covers requirements across multiple frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).

Who Is Affected – Government agencies, financial services firms, NGOs, think‑tanks, and any organization that communicates with Ukraine‑supporting entities.

Recommended Actions

  • Review and update phishing‑simulation programs to include “RedFlick”‑style payloads and mass‑mailing tactics.
  • Enforce strict email‑authentication (DMARC, SPF, DKIM) and deploy anti‑phishing gateways that can sandbox password‑protected archives.
  • Capture and retain evidence of training completion, simulated‑phish results, and email‑filter logs for audit readiness. Source: The Record

Technical Notes – Attack vector: phishing emails (mass‑mailing platform) → password‑protected archive → RedFlick malware → scheduled‑task backdoor (CosmicPulse). No public CVE; technique is novel malware delivery. Source: Microsoft security blog

📰 Original Source
https://therecord.media/russia-hackers-ukraine-blizzard ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →