Russian FSB‑linked “Star Blizzard” Scales Up Phishing Campaigns Targeting Ukraine Supporters and Global Allies
What Happened – Microsoft reports that the state‑backed group known as Star Blizzard (also called Callisto/ColdRiver) has shifted from highly‑targeted spear‑phishing to mass‑mailing campaigns, launching at least 13 large‑scale operations since January 2026. The group now uses compromised web‑site accounts and a new “RedFlick” delivery method that drops a password‑protected archive; opening the archive installs the CosmicPulse backdoor via scheduled tasks. Over 100 organizations in the U.S., U.K., NGOs, think tanks, governments and financial institutions have been hit.
Why It Matters for Trust & Control Assurance
- This activity tests the effectiveness of an organization’s security‑awareness program and its ability to detect and block phishing‑derived malware – a core control area for continuous assurance.
- Automated, high‑volume phishing defeats ad‑hoc training; continuous monitoring of email‑security controls and documented awareness metrics provide defensible evidence for audits.
- Mapping the incident to a single control objective—people‑centric security awareness and training—covers requirements across multiple frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).
Who Is Affected – Government agencies, financial services firms, NGOs, think‑tanks, and any organization that communicates with Ukraine‑supporting entities.
Recommended Actions
- Review and update phishing‑simulation programs to include “RedFlick”‑style payloads and mass‑mailing tactics.
- Enforce strict email‑authentication (DMARC, SPF, DKIM) and deploy anti‑phishing gateways that can sandbox password‑protected archives.
- Capture and retain evidence of training completion, simulated‑phish results, and email‑filter logs for audit readiness. Source: The Record
Technical Notes – Attack vector: phishing emails (mass‑mailing platform) → password‑protected archive → RedFlick malware → scheduled‑task backdoor (CosmicPulse). No public CVE; technique is novel malware delivery. Source: Microsoft security blog