Russian FSB-Linked Hackers Ramp Up Phishing Campaigns Targeting Ukraine Supporters
Microsoft has revealed that Star Blizzard, a Russian hacking group linked to the FSB, has significantly expanded its phishing operations in 2026. Previously known for narrow, highly targeted spear-phishing, the group now sends bulk phishing campaigns of tens or hundreds of emails at once, affecting more than 100 organisations, mostly in the US and UK. Targets include Ukrainian individuals and institutions, along with NGOs, think tanks, governments and financial institutions that support Ukraine.
The shift appears to stem from the group adopting a mass-mailing phishing platform that automates attacks, with at least 13 large-scale campaigns identified since January. The hackers have also changed their infrastructure, using accounts on compromised websites rather than free email services to contact victims. Early campaigns impersonated Ukrainian authorities with fake tax audit or fine notices, while later ones used fraudulent conference or event invitations supposedly from legitimate think tanks and NGOs, sometimes disguised as internal staff communications.
Microsoft suggests Star Blizzard may have initially tested its new tactics on Ukrainian targets before expanding globally, indicating the campaign could continue to grow in scale and reach beyond its current victims.