Microsoft reports that the Russia-linked group Star Blizzard expanded from highly targeted spear-phishing to larger email campaigns aimed at Ukraine supporters globally. Lures included tax-audit/unpaid-fine notices and fake conference invitations, followed by a password-protected archive that installs malware with just one click.
How the campaign unfolded
Star Blizzard, also tracked as Callisto or ColdRiver and linked to Russia's FSB, shifted from narrowly targeted spear-phishing to broader email campaigns sent in batches of tens or hundreds at a time. Early campaigns in January and February targeted users of the Ukrainian email provider Ukr.net, impersonating Ukrainian authorities with claims that the recipient faced a tax audit or had an unpaid fine. Beginning in March, the group broadened its targeting beyond Ukraine, using fake invitations to conferences or events supposedly organized by reputable think tanks or NGOs. In some cases, several people at the same organization were targeted, with messages disguised as internal communications.
The follow-up infection chain
Once a victim replies to one of these initial lures, Star Blizzard sends a follow-up containing a password-protected archive. Opening a file inside that archive triggers RedFlick, which uses scheduled tasks on the victim's computer to install the group's CosmicPulse backdoor while making the activity harder to detect. Notably, this method requires only one action from the victim, a simpler path to compromise than the group's earlier approach.
Why this scales so effectively
This attack succeeds because it layers believable pretexts on top of social engineering rather than relying on technical exploits. Threats of a tax audit or fine create urgency that pushes recipients to respond without verifying the sender. Conference invitations exploit professional curiosity and the credibility people associate with think tanks and NGOs. Using accounts created on compromised websites, rather than only impersonating free webmail providers, also helps the lures appear more legitimate. Once a reply is sent, the password-protected archive can slip past some automated scanning, and the single-click installation reduces the number of decisions a victim has to make before compromise occurs.
What defenders should watch for
- Unsolicited emails threatening an audit or fine that pressure quick action
- Sender addresses that do not match official government domains
- Unexpected conference or event invitations asking you to reply or continue an email thread
- Messages styled as internal communications sent to multiple coworkers
- Password-protected archives arriving after you've replied to an email thread
Building organizational resistance
Staff across government, NGO, think tank, finance, and policy roles should treat replies to unsolicited audit, fine, or invitation emails as the first risk point, not just attachment handling. Verify claims of fines or audits through known official channels rather than by replying. Train employees to escalate password-protected archives to IT or security for inspection instead of opening them directly, and reinforce that an internal-looking email does not guarantee a legitimate sender, especially when multiple colleagues receive similar messages.
Key findings
- Star Blizzard (aka Callisto/ColdRiver), linked to Russia’s FSB, expanded to larger-scale phishing campaigns (“tens or hundreds of emails at a time”).
- Early 2026 campaigns targeted Ukr.net users with messages impersonating Ukrainian authorities about “a tax audit” or “an unpaid fine.”
- From March, targeting broadened beyond Ukraine with “fake invitations to conferences or events supposedly organized by reputable think tanks or NGOs,” including emails disguised as internal communications.
- Attackers used “accounts created on compromised websites” rather than only free webmail impersonation.
- After a victim replies, the attacker sends a “password-protected archive”; opening it triggers “RedFlick,” which uses scheduled tasks to install the “CosmicPulse backdoor.”
- The newer malware-delivery method “requires only one action from the victim,” making compromise easier than the prior “ClickFix” approach.
Who’s being targeted
- Commonly targeted roles: All employees (NGOs/government/think tanks), Executives and executive assistants, Finance and Legal/Compliance, Public affairs/Policy teams, IT and Helpdesk (triage of suspicious attachments).
- Affected industries: Government, Nonprofits/NGOs, Think tanks, International affairs/Policy organizations, Financial institutions.
- Attack channels: email.
- Impersonated: Ukrainian authorities (government/tax or fines office), Reputable think tank or NGO (conference organizer), Same person/organization from the earlier email thread.
Red flags to watch for
- Unexpected threat of audit/fine sent via email
- Sender account not from an official government domain (may be an account created on a compromised site)
- Pressure to respond quickly to avoid penalties
- Unsolicited invitation with vague logistics or urgency
- Message appears to come from a reputable organization but sender is unusual or recently created
- Multiple people at the same organization targeted with “internal” style wording
- Password-protected archive sent after you reply (common to bypass scanning)
- Unexpected attachment type/archived file requiring you to open an internal file
- Email thread escalates to executing/opening files rather than normal coordination
Frequently asked questions
Who is Star Blizzard and what did they change in their attacks?
Star Blizzard, also known as Callisto or ColdRiver and linked to Russia's FSB, expanded from highly targeted spear-phishing to larger campaigns sending tens or hundreds of emails at a time.
What lures did Star Blizzard use in these campaigns?
Early campaigns impersonated Ukrainian authorities with claims of a tax audit or unpaid fine, while later campaigns used fake invitations to conferences or events supposedly organized by reputable think tanks or NGOs.
How does the RedFlick malware get installed?
After a victim replies to the initial phishing email, the attacker sends a password-protected archive. Opening a file inside it triggers RedFlick, which uses scheduled tasks to install the CosmicPulse backdoor, requiring only one action from the victim.
Why is this attack harder to detect than before?
The new delivery method requires only one action from the victim, compared to the group's prior approach, and the password-protected archive can help the malicious file bypass email scanning.
Read the video transcript
You get an email: “Notice: You are subject to a tax audit” or “unpaid fine.” Looks urgent, looks official… and it’s a trap. This is Star Blizzard using their RedFlick trick: you reply, they send a password‑protected archive, you open it once, and it quietly installs their CosmicPulse backdoor. Same move with fake conference invites: “Invitation: Conference registration details” from a think tank or NGO, or even phrased like an internal email, all pushing you to reply so they can send that archive. If any audit, fine, or invite email leads to a password‑protected archive, stop and forward it to IT or Security, do not open it.