Microsoft reports that the Russia-linked group Star Blizzard (COLDRIVER) has expanded from small, highly targeted spear-phishing to larger phishing “blasts” hitting NGOs, think tanks, and government organizations. The campaigns use believable email themes like event invitations, tax audits, and payment notices to get a single click, then quietly install a custom backdoor that’s harder to spot.
Key findings
- Star Blizzard (COLDRIVER) moved from narrow spear-phishing to mass phishing campaigns (tens to hundreds of emails).
- Microsoft attributes at least 13 large-scale campaigns since January 2026, impacting more than 100 organizations (mostly US and UK).
- Email lures include “exclusive event invitations, tax audits, and payment notices.”
- A delivery method called “RedFlick” requires only a single user interaction and uses scheduled tasks to install the “CosmicPulse” backdoor more quietly.
Who’s being targeted
- Commonly targeted roles: Executive leadership, Government staff, NGO program staff, Think-tank researchers/analysts, Finance/AP, Legal, Executive assistants.
- Affected industries: Government, Nonprofits/NGOs, Think tanks.
- Attack channels: email.
- Impersonated: Event organizer (conference/invitation sender), Tax authority/auditor, Payments/billing sender (vendor or internal payments team).
Awareness takeaways
- Treat “official-sounding” invitations, audits, and payment emails as high-risk and verify through known channels before clicking.
- Assume one click can be enough to compromise a device, report suspicious emails even if you only interacted once.
- Prepare for broad, mass-mailed campaigns (not just ‘targeted spear-phishing’) and ensure staff know how to report suspected phishing quickly.
Red flags to watch for
- Unexpected event invitation pushing you to click immediately
- Vague sender identity or mismatched email domain
- Any prompt to enable content or approve a “single step” action to view details
- Tax/audit language used to create urgency or fear
- Generic wording (no case number, no clear organizational identifiers)
- Request to click to view documents rather than using established official channels
- Unexpected payment notice not tied to a known invoice or vendor
- Pressure to act quickly via a link in the email
- Email sent broadly to multiple recipients rather than normal payment workflows
Read the video transcript
You’re not just getting random spam anymore. Star Blizzard is blasting real-looking invites and tax notices at organizations like ours. Microsoft’s seen at least 13 of these mass campaigns since 2026, tens to hundreds of emails each, using hooks like exclusive policy events, tax audits, or payment notices to land just one click. Here’s the nasty part: their RedFlick trick needs only one interaction. You click RSVP or 'view audit', it quietly sets up a scheduled task and drops their CosmicPulse backdoor on your device. If any invite, audit, or payment email feels off, don’t click anything, forward it to the security team and let us check it first.