Russian State Hackers Widen Net with New Malware and Mass Phishing Tactics
Microsoft research has found that Star Blizzard, a hacking group linked to Russia's Federal Security Service, has changed its approach in 2026, moving beyond narrowly targeted spear-phishing to much larger phishing campaigns. These new campaigns can involve hundreds of emails at once, suggesting the group has adopted an automated mass-mailing platform to widen its pool of potential victims.
The group's new malware, dubbed RedFlick, is notable because it only requires a single click or interaction from a victim to succeed, making it easier to compromise targets than more complex attacks. Common lures include invitations to exclusive events, as well as fake tax audit notices, payment demands and fine notifications. Microsoft says it has tracked at least 13 distinct large-scale phishing campaigns since January 2026, affecting more than 100 organisations, mostly in the United States and United Kingdom, including NGOs, think tanks, governments and financial institutions supporting Ukraine.
The campaigns initially focused on Ukrainian targets before expanding globally by spring, which Microsoft suggests may indicate Ukraine was used as a testing ground before the group broadened its reach.