Microsoft said that the Russian threat group Star Blizzard, also known as SEABORGIUM, changed its tactics between January and August 2026 to expand the scope of its phishing and reduce the chances of its operations being detected. The changes included shifting from precisely targeted phishing campaigns to campaigns sending dozens or hundreds of messages, creating accounts on compromised websites, and adopting a new technique for delivering malware that Microsoft named RedFlick.
According to Microsoft’s analysis, the campaigns targeted Ukrainian individuals and organizations, as well as nongovernmental organizations, research centers, governments, and financial institutions in other countries, particularly entities politically or financially associated with supporting Ukraine. The observed activities affected more than 100 organizations, most of them in the United States and the United Kingdom, while international entities working in politics, security, and government affairs continued to be targeted.
From Selective Phishing to Large-Scale Campaigns
Microsoft observed at least 13 broad phishing campaigns since January 2026. Some campaigns began with Ukrainian-language messages disguised as notifications about a tax audit or fines, then expanded in March to messages pretending to be invitations to closed meetings and conferences organized by a known research center or nongovernmental organization. Several people within the same organization were also targeted, sometimes with messages that appeared to be internal communications sent by the targeted entity.
After the recipient interacted with the initial message, the attacker would typically send a password-protected RAR or ZIP archive. The password appeared inside an image attached to the subsequent message. Since March, Microsoft observed the use of accounts created on websites hosted through compromised CPanel and WordPress installations, rather than relying exclusively on free email services. The company assesses with high confidence that Star Blizzard compromised those websites to use them for sending messages.
What Does RedFlick Add?
RedFlick relies on creating several scheduled tasks in Windows to install and run the malicious component CosmicPulse, a Python-written backdoor also known as YESROBOT, while the downloader associated with it was known by the names NOROBOT and BAITSWITCH. This chain differs from previous ClickFix campaigns, which required the victim to perform several steps; the new flow requires only a single interaction, reducing friction and increasing the likelihood that the compromise will be completed.
The campaigns used VHDX files, compressed archives, and LNK files disguised as PDF documents, and also ran tools such as conhost.exe, curl, and SSH to download MSI installers. In later stages, the payload was concealed inside a PDF file, where PowerShell searched for a specific header and extracted Base64 data encrypted symmetrically before executing it. In April, the installer created three scheduled tasks disguised as legitimate network component names: Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor, to exfiltrate basic information about the device, support execution through WebDAV, and run CosmicPulse.
Why Does This Development Matter?
The most important point is not the emergence of new malware itself, but the combination of operational expansion and a simplified infection path. Larger campaigns increase the number of targets, while RedFlick reduces the number of actions required from the user, and scheduled tasks and payload-obfuscation mechanisms provide the attackers with additional ways to bypass email and endpoint defenses. This indicates Star Blizzard’s ability to modify its tactics after its previous campaigns were exposed, while maintaining the same espionage objective.
Microsoft recommends that the most exposed entities, particularly governments, nongovernmental organizations, and research centers associated with Ukraine-related issues, use phishing-resistant authentication, apply Conditional Access policies, and enable Safe Links, Safe Attachments, and endpoint detection and response solutions. It also calls for monitoring unusual scheduled tasks, curl and SSH downloads that are inconsistent with normal work, and running advanced hunting queries and the indicators of compromise published in its report.
These recommendations remain partly tied to Microsoft products, and detection queries may also generate alerts unrelated to Star Blizzard. Investigators therefore need to verify the context before treating any match as evidence of compromise, while the published details remain a snapshot of activity observed during 2026 and are not a guarantee that the group will retain the same methods.