News / Cybersecurity
Star Blizzard shifts to large-scale phishing campaigns using RedFlick and CosmicPulse techniques Published on 29 September 2026 by Christ-loisele (3 min read)
The Russian cybercriminal group Star Blizzard, linked to the FSB, abandoned targeted attacks in favor of large-scale campaigns in 2026, exploiting the RedFlick method to deploy the CosmicPulse malware. Over 100 American and British organizations were affected, with targets including Ukraine and its international supporters.
Video: Star Blizzard (Threadwave - Topic, YouTube)
A tactical shift toward automated, less interactive attacks
Star Blizzard has significantly altered its methods since January 2026, according to analyses by Microsoft and the United States Cybersecurity and Infrastructure Agency (CISA) . The group, attributed to the Russian Federal Security Service (FSB) Centre 18 , has abandoned targeted spear-phishing campaigns in favor of large-scale phishing operations. The RedFlick technique now allows the deployment of the CosmicPulse malware with a single user interaction, compared to multiple steps previously required with the ClickFix method.
Unlike previous approaches, RedFlick exploits Windows scheduled tasks to install CosmicPulse, a Python-written backdoor. The 2026 campaigns used email subjects in Ukrainian and English, with varied lures: tax-related notifications such as « Повідомлення про результати податкової перевірки » (tax audit results) or « списання з Вашого рахунку за оплату штрафу » (debit for fine payment), as well as invitations to fictional events like « Invitation to an IISS [Private Roundtable/Closed-Door Discussion] on European Security » .
Star Blizzard has reduced the infection process to a single user interaction thanks to RedFlick, making its attacks more effective and harder to detect.
Illustrative photo: network cables (Jakub T. Jankiewicz, CC BY-SA 4.0)
Expanded targets: from Ukraine to international organizations
Star Blizzard’s attacks are no longer limited to Ukrainian individuals and institutions. The group now targets international NGOs, Western think tanks, governments, and financial institutions supporting Ukraine , as documented by Microsoft . Over 100 organizations, primarily in the United States and the United Kingdom , have been affected by these RedFlick campaigns since early 2026.
A notable feature is the use of compromised websites to send phishing emails, a more discreet method than using Protonmail or Microsoft consumer addresses. Passwords for protected archives are even provided as images in emails , a technique aimed at bypassing automated analysis. The scheduled tasks created by RedFlick carry innocuous names like « Internet Quality Test Connection » or « System Health Monitor » , enhancing their credibility with victims.
What this means here: increased risks for African administrations and businesses
While Star Blizzard’s primary targets remain, for now, linked to Ukraine and its allies, African organizations, particularly those involved in partnerships with Western institutions or international support programs, could be exposed . Mass phishing campaigns, combined with tailored lures (tax-related, professional events), could affect employees of Beninese administrations or West African businesses collaborating with European or American actors.
The automation of attacks via RedFlick reduces the need for advanced technical skills among cybercriminals, thus increasing the volume and speed of intrusions . Local businesses using outdated Windows solutions or platforms like WordPress or cPanel without enhanced monitoring would be particularly vulnerable. Furthermore, the use of compromised websites as an attack vector underscores the importance for African organizations to secure their web infrastructure and train their teams on new phishing tactics, particularly those exploiting contextual lures (tax-related, diplomatic).
A coordinated response from cybersecurity stakeholders
The revelations about RedFlick and CosmicPulse have triggered cross-alerts. The Google Threat Intelligence Group had already published a report on the COLDCOPY malware in October 2025, while Microsoft now provides direct notifications to targeted clients, along with technical recommendations. These developments illustrate an evolution of the group’s intelligence-driven tactics, techniques, and procedures (TTPs) , likely in response to countermeasures deployed since 2023.
For African organizations, these developments highlight the imperative to adopt advanced threat detection solutions and train teams in incident response protocols . Star Blizzard’s shift toward less interactive, more scalable attacks could encourage cybercriminals to replicate these methods in other regions, including Africa.
Sources