Star Blizzard Shifts to Mass Phishing Lures

About DFIR · High sophistication
Last updated October 1, 2026

Microsoft reports that the Russia-linked group Star Blizzard (COLDRIVER) has expanded from small, highly targeted spear-phishing to larger phishing “blasts” hitting NGOs, think tanks, and government organizations. The campaigns use believable email themes like event invitations, tax audits, and payment notices to get a single click, then quietly install a custom backdoor that’s harder to spot.

Key findings

  • Star Blizzard (COLDRIVER) moved from narrow spear-phishing to mass phishing campaigns (tens to hundreds of emails).
  • Microsoft attributes at least 13 large-scale campaigns since January 2026, impacting more than 100 organizations (mostly US and UK).
  • Email lures include “exclusive event invitations, tax audits, and payment notices.”
  • A delivery method called “RedFlick” requires only a single user interaction and uses scheduled tasks to install the “CosmicPulse” backdoor more quietly.

Who’s being targeted

  • Commonly targeted roles: Executive leadership, Government staff, NGO program staff, Think-tank researchers/analysts, Finance/AP, Legal, Executive assistants.
  • Affected industries: Government, Nonprofits/NGOs, Think tanks.
  • Attack channels: email.
  • Impersonated: Event organizer (conference/invitation sender), Tax authority/auditor, Payments/billing sender (vendor or internal payments team).

Awareness takeaways

  • Treat “official-sounding” invitations, audits, and payment emails as high-risk and verify through known channels before clicking.
  • Assume one click can be enough to compromise a device, report suspicious emails even if you only interacted once.
  • Prepare for broad, mass-mailed campaigns (not just ‘targeted spear-phishing’) and ensure staff know how to report suspected phishing quickly.

Red flags to watch for

  • Unexpected event invitation pushing you to click immediately
  • Vague sender identity or mismatched email domain
  • Any prompt to enable content or approve a “single step” action to view details
  • Tax/audit language used to create urgency or fear
  • Generic wording (no case number, no clear organizational identifiers)
  • Request to click to view documents rather than using established official channels
  • Unexpected payment notice not tied to a known invoice or vendor
  • Pressure to act quickly via a link in the email
  • Email sent broadly to multiple recipients rather than normal payment workflows
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re not just getting random spam anymore. Star Blizzard is blasting real-looking invites and tax notices at organizations like ours. Microsoft’s seen at least 13 of these mass campaigns since 2026, tens to hundreds of emails each, using hooks like exclusive policy events, tax audits, or payment notices to land just one click. Here’s the nasty part: their RedFlick trick needs only one interaction. You click RSVP or 'view audit', it quietly sets up a scheduled task and drops their CosmicPulse backdoor on your device. If any invite, audit, or payment email feels off, don’t click anything, forward it to the security team and let us check it first.

Categories

Similar attacks

ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Fake CAPTCHA Tricks Users Into Running TerminalFix

Fake CAPTCHA Tricks Users Into Running TerminalFix

Attackers used a fake Cloudflare “verify you are human” overlay to copy a command to victims’ clipboards and trick them into pasting it into Windows Terminal/PowerShell. The command kicked off a multi-stage infection chain, including downloading payloads hidden inside PNG images, establishing…

August 31, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake Notepad++ Plugin Used in Ukraine Phish

Fake Notepad++ Plugin Used in Ukraine Phish

CERT-UA reports a real phishing campaign linked to Russia-aligned actor UAC-0099 targeting Ukrainian organizations. Victims receive an email with an image attachment that leads (via a link shortener) to a file-sharing download, where a disguised script installs a trojanized Notepad++ plugin and…

July 24, 2026