Russia's Star Blizzard drops the ClickFix act and switches to one-click RedFlick malware

Microsoft says the FSB-linked crew has scaled up its phishing and streamlined how it plants its CosmicPulse backdoor. More than 100 organisations in the US and UK have been hit this year.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit laptop screen showing a generic email inbox with a red-tinted paperclip attachment icon, c
Share

Key points

  • Microsoft says a Russian intelligence hacking crew called Star Blizzard has hit more than 100 organisations in the US and UK during 2026 using a new one-click malware trick it calls RedFlick.
  • The group is assessed by US, UK, Australian, Canadian and New Zealand cyber agencies to work for Centre 18 of Russia's Federal Security Service (FSB), the intelligence service's cyber arm.
  • RedFlick installs a custom backdoor called CosmicPulse with a single click from the victim, replacing an older method that required several steps.
  • Lures spotted this year include fake invitations to Chatham House, Atlantic Council and IISS events, plus Ukrainian-language notices about tax audits and water shutoffs.
  • The Atlantic Council campaign pushed a separate iOS backdoor Microsoft calls DarkSword, showing the group is experimenting on mobile as well.

A Russian government hacking group best known for quiet, hand-crafted attacks on think tanks and diplomats has changed tactics. It's now sending phishing emails by the hundred and using a slicker way to plant its spying tools.

That's the picture from a report published this week by the Microsoft Threat Intelligence team, which tracks the group as Star Blizzard. Other researchers call it Callisto or SEABORGIUM. Western cyber agencies say it answers to Centre 18 of the FSB, Russia's main intelligence service. Our coverage of FSB-linked activity has grown sharply this quarter: we've reported on the bloc of EU, UK and French sanctions against Russian intelligence operations and logged 27 Russia-tagged stories in the last 90 days.

Who is Star Blizzard and why does it matter?

Star Blizzard is a spying operation, not a ransomware crew. It steals credentials and documents from people whose work touches Russian interests: Ukrainian officials, NGOs, journalists and staff at Western foreign policy institutes.

Microsoft says more than 100 organisations, mostly in the United States and United Kingdom, have been targeted this year, consistent with the group's long-running remit.

What is RedFlick, in plain words?

RedFlick is the name Microsoft gives to the group's new delivery method. It installs a custom backdoor called CosmicPulse that lets the hackers access the machine remotely. Malware is software written to spy or cause harm.

The key change is friction. Star Blizzard used to rely on ClickFix, a technique that tricks victims into copying and pasting commands into their own machine. It works, but it asks a lot. RedFlick needs one click on a file inside a password-protected archive, and the infection begins. We covered ClickFix's own evolution on 21 September in a separate campaign.

Think of it as the difference between a scam that asks you to fill in a five-page form and one that just asks you to sign at the bottom. More people sign.

How does the attack actually reach people?

It starts with a friendly email. Not a malicious link, not an attachment: just an invitation. Only when the recipient replies does the second email arrive, carrying a password-protected RAR or ZIP file. The password sits in the email as an image, which helps it slip past scanners that read text. Microsoft lists lures used through 2026:

Month Lure subject Who was targeted
March Invitation to an IISS roundtable on European security Officials, academics, NGOs
March Atlantic Council closed-door discussion Foreign policy community
June Chatham House London Conference 2026 Think tanks, parliaments
July Notice about a Kyiv water supply shutdown Kyiv hotels
August Payment advice note dated 06.08.2026 An international financial organisation

Open the archive and click the file, and RedFlick sets up scheduled tasks that quietly fetch and run CosmicPulse. The March Atlantic Council campaign took a different route and pushed the iOS backdoor DarkSword instead. Star Blizzard's experimenting on mobile is worth watching.

Is this really a new attack?

Not really. Stripped of the codenames, RedFlick is a password-protected archive with a booby-trapped file inside, delivered after a bit of social rapport. That pattern predates most people reading this. What's new is the scale, the automation and the discipline of the pretext.

Star Blizzard has stopped behaving like a boutique intelligence unit and started behaving like a spam operation with an FSB badge. Higher volume means more noise, giving defenders more chances to catch it, but it also means more successful hits before anyone does. If you work at a think tank, an NGO or a Ukraine-adjacent ministry, treat any unsolicited invitation to a closed-door roundtable as hostile until proven otherwise. Never open an archive whose password arrived as a picture.

© 2026 Threat Vectr