Skip to content
Bellator Cyber Guard
News8 min readStandard

Star Blizzard's New RedFlick Chain Deploys CosmicPulse

Russian APT Star Blizzard now uses a RedFlick infection chain to deploy the CosmicPulse backdoor in larger-scale phishing campaigns.

By Bellator Cyber Guard Security Team
Star Blizzard's New RedFlick Chain Deploys CosmicPulse - star blizzard redflick infection chain update 2026

Russian State Hackers Deploy New RedFlick Infection Chain

Star Blizzard, a Russian state-sponsored hacking group linked by Western government agencies to Russia's Federal Security Service (FSB), has adopted a new infection chain called RedFlick to deliver a backdoor known as CosmicPulse, according to reporting published September 30, 2026. The group has reportedly expanded the scale of its phishing campaigns to distribute the malware, signaling a shift toward broader targeting rather than narrowly scoped operations against a handful of high-value individuals.

Star Blizzard is the threat-intelligence name Microsoft assigns to a group also tracked in earlier government and industry advisories as SEABORGIUM and Callisto Group. In December 2023, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the National Security Agency (NSA), and the UK National Cyber Security Centre (NCSC) jointly attributed the group's spear-phishing activity to Center 18 of Russia's FSB, describing a pattern of credential-harvesting campaigns aimed at government officials, journalists, academics, and non-governmental organizations, particularly those with a focus on Russia and Eastern Europe.

The newly reported RedFlick infection chain and CosmicPulse backdoor appear to represent an evolution of the group's toolkit rather than a change in its overall objective, which has historically centered on long-term espionage and intelligence collection through compromised email accounts and stolen credentials.

Key Takeaway

Star Blizzard's reported move to larger-scale phishing campaigns using a new RedFlick to CosmicPulse infection chain means organizations that assumed they were too small to draw nation-state attention should reassess that assumption, especially if they handle sensitive client data, government contracts, or communications tied to foreign policy, journalism, or advocacy work.

Why the Shift to Larger-Scale Phishing Matters

Nation-state groups like Star Blizzard have traditionally run tightly targeted campaigns against a relatively small number of individuals chosen for their access or influence. Reported expansion into larger-scale phishing to push CosmicPulse suggests the group is casting a wider net, which raises the odds that mid-sized organizations, contractors, and third-party service providers get caught up in a campaign even when they are not the primary intended target.

An infection chain like RedFlick typically refers to the sequence of steps an attacker uses to move from an opened email to persistent access on a victim's device: a phishing lure, an initial payload, and follow-on backdoor deployment. The specific technical mechanics of RedFlick have not been independently detailed in the reporting reviewed here, but pairing it with a named backdoor indicates the group has built or refined tradecraft for establishing and maintaining footholds after an initial compromise.

Star Blizzard's documented history is instructive. The 2023 joint advisory from CISA, the FBI, NSA, and NCSC described a group that relies heavily on convincing spear-phishing emails, often impersonating known contacts or legitimate services, to harvest credentials and session cookies, then uses that access to monitor and exfiltrate sensitive communications over extended periods. The advisory also noted the group's use of look-alike domains and hidden email-forwarding rules to retain visibility into a victim's inbox even after a password reset.

What Healthcare Practices, Tax Firms, and Small Businesses Should Do Now

Organizations that handle regulated or sensitive data, including healthcare providers, tax and accounting firms, legal practices, and government contractors, should treat this reporting as a reminder to revisit baseline email security controls rather than wait for a confirmed direct threat.

  • Enforce phishing-resistant multi-factor authentication (MFA). Credential and session-cookie theft are central to how groups like Star Blizzard maintain access; hardware security keys or FIDO2-based authentication reduce the value of a stolen password.
  • Audit inbox rules and forwarding settings. Attackers who gain access to an account often create hidden mail-forwarding rules to monitor communications quietly. Periodic review of these settings across your email tenant can catch compromise early.
  • Train staff to scrutinize sender identity, not just links. State-linked phishing campaigns frequently impersonate trusted contacts or familiar services rather than relying on obviously malicious attachments, so link-scanning tools alone are not sufficient.
  • Watch endpoints for backdoor persistence. Because CosmicPulse is described as a backdoor rather than a one-time payload, endpoint detection and response (EDR) tooling that flags unusual outbound connections or newly created scheduled tasks is more useful than signature-based antivirus alone.
  • Review third-party access. If your organization works with government agencies, journalists, or advocacy groups that may be higher-priority targets, limit what access those partners have to your systems to what is strictly necessary.

No technical indicators of compromise or victim list have been published in the reporting reviewed for this analysis, so organizations should treat this as a signal to strengthen general defenses rather than a confirmed direct threat requiring emergency response. Readers who want authoritative detail on Star Blizzard's established tactics can consult the joint advisory from CISA, the FBI, NSA, and the UK NCSC, which remains the primary government reference point for this group's techniques.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Phishing & email security

Recognize manipulation, protect email accounts, and give people a clear way to report suspicious messages.

Learn first. Decide when you are ready.

Keep learning, or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.