Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A Russian state-backed hacking group has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware, according to Microsoft.

The hacking group, known as Star Blizzard, has targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments and financial institutions that support Ukraine politically or financially. In a report published Tuesday, Microsoft said the activity has affected more than 100 organizations, primarily in the U.S. and UK.

Star Blizzard, also tracked as Callisto and ColdRiver, has previously been linked by Western governments to Russia’s Federal Security Service, or FSB. The group has been active since at least 2017 and is known for targeting government agencies, NGOs and organizations involved in international affairs.

Since the beginning of 2026, researchers have seen the hackers significantly expand their operations, moving beyond highly targeted spear-phishing attacks to campaigns involving tens or hundreds of emails at a time.

Researchers said the shift likely reflects Star Blizzard’s adoption of a mass-mailing phishing platform that allows the group to automate its attacks and reach more potential victims. Microsoft has identified at least 13 such large-scale campaigns since January.

Star Blizzard has also changed how it sends phishing messages. Since March, researchers have observed hackers using accounts created on compromised websites to contact targets. The group previously tended to rely on free email services to create accounts impersonating people familiar to potential victims, such as political figures, academics or former diplomats.

The earliest campaigns, detected in January and February, targeted users of the Ukrainian email provider Ukr.net. The hackers impersonated Ukrainian authorities and sent messages claiming that recipients faced a tax audit or had an unpaid fine.

Beginning in March, Star Blizzard expanded its targeting beyond Ukraine, frequently sending fake invitations to conferences or events supposedly organized by reputable think tanks or NGOs. In some cases, the hackers targeted several people at the same organization and disguised the phishing emails as internal communications.

“The actor’s shift from Ukraine-focused operations to global targets could indicate Star Blizzard initially targeted Ukraine to test their new capabilities,” Microsoft said.

The hackers have also adopted a new way of delivering malware that Microsoft calls RedFlick.

Once a victim responds to an initial phishing email, Star Blizzard typically sends a follow-up containing a password-protected archive. Opening a file inside the archive triggers RedFlick, which uses scheduled tasks on the victim’s computer to install the group’s CosmicPulse backdoor while making the activity harder to detect.

The new method requires only one action from the victim. Star Blizzard’s previous infection method, known as ClickFix, required victims to complete several steps before CosmicPulse could be installed.

“Combined with the actor’s shift toward large-scale phishing operations during the same period, these changes likely improve Star Blizzard’s ability to reach more targets, evade detection, and increase the likelihood of successful compromise,” Microsoft said.



Click Here For The Original Source.

——————————————————–

..........

.

.