Executive Summary
Russian state-sponsored threat actor Star Blizzard (linked to FSB Center 18) conducted sophisticated phishing campaigns throughout 2026, targeting over 100 organizations primarily in the U.S. and U.K. with fake event invitations. The group employed a new technique called RedFlick to deploy CosmicPulse backdoors through compromised WordPress and cPanel websites, using scheduled tasks to maintain persistence on Windows systems. At least one confirmed infection occurred among organizations tied to Ukraine policy and support.
This campaign represents a significant evolution in state-sponsored cyber espionage tactics, demonstrating increased sophistication in social engineering and malware delivery methods. The targeting of Ukraine-related entities amid ongoing geopolitical tensions highlights the persistent threat to critical infrastructure and policy organizations.
Why This Matters Now
State-sponsored groups are rapidly evolving their attack methods, with Star Blizzard's RedFlick technique representing a new standard for persistence and evasion that other threat actors will likely adopt, requiring immediate updates to detection and prevention strategies.
Attack Path Analysis
Star Blizzard (FSB Center 18) conducted a sophisticated phishing campaign using fake event invitations to deliver CosmicPulse backdoor via the RedFlick technique. Attackers compromised WordPress/cPanel sites for C2, used LNK files disguised as PDFs to execute MSI installers, established persistence through scheduled tasks, maintained command and control via WebDAV and remote servers, and positioned for data exfiltration targeting Ukraine-related organizations across 100+ entities.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers sent fake event invitations appearing from legitimate organizations (Chatham House, Atlantic Council) with password-protected archives containing LNK files disguised as PDFs that executed hidden commands to download MSI installers
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
Scheduled Task
Control Panel
Web Protocols
Process Injection
Match Legitimate Name or Location
Credentials from Web Browsers
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.01(g)
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: IA-3
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
ISO 27001:2022 – Web Filtering
Control ID: A.8.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Russian Star Blizzard's cyber espionage targeting 100+ organizations poses critical risks to government communications, requiring enhanced zero trust segmentation and encrypted traffic monitoring.
Civic/Social Organization
NGOs and think tanks face direct targeting through fake event invitations, necessitating egress security controls and threat detection capabilities against sophisticated phishing campaigns.
Information Technology/IT
IT infrastructure vulnerabilities exposed through RedFlick technique require multicloud visibility controls and Kubernetes security to prevent lateral movement and data exfiltration.
Financial Services
International financial organizations targeted with payment notices need comprehensive threat detection, encrypted traffic protection, and compliance with HIPAA and PCI security frameworks.
Sources
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoorhttps://thehackernews.com/2026/09/russias-star-blizzard-targets-100.htmlVerified
- Star Blizzard refines phishing and malware delivery with the REDFLICK techniquehttps://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/Verified
- Star Blizzard continues spear-phishing campaignshttps://www.ncsc.gov.uk/news/star-blizzard-continues-spear-phishing-campaignsVerified
- Spearphishing via fake URC 2026 invitations targets Ukrainian CSOshttps://dslua.org/publications/spearphishing-via-fake-urc-2026-invitations-targets-ukrainian-csos/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of Star Blizzard's CosmicPulse campaign by constraining lateral movement and limiting access to sensitive workloads through microsegmentation. The comprehensive east-west traffic enforcement and controlled egress policies could have significantly reduced attacker reach across the 100+ targeted organizations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial payload execution may have been constrained through workload isolation, limiting the scope of compromise to individual segments rather than broad network access
Control: Zero Trust Segmentation
Mitigation: Privilege escalation impact would likely be reduced through microsegmentation policies that limit cross-workload access even with elevated system privileges
Control: East-West Traffic Security
Mitigation: Lateral movement between workloads would likely be significantly constrained through granular east-west traffic policies that restrict inter-segment communication paths
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be reduced through comprehensive visibility across cloud environments and granular access controls that limit external connectivity
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration scope would likely be constrained through controlled egress policies that limit outbound data flows and restrict unauthorized external communications
Overall campaign impact would likely be significantly reduced with compromised assets contained within specific network segments and limited cross-organizational reach
Impact at a Glance
Affected Business Functions
- Government Policy Development
- International Relations
- Research and Analysis
- Stakeholder Communications
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of sensitive government communications, policy documents, research data, and stakeholder contact information from over 100 targeted organizations, primarily think tanks, NGOs, and government bodies focused on Ukraine policy. The FSB-affiliated threat actor likely accessed email credentials and session tokens to facilitate ongoing intelligence collection operations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to block unauthorized outbound communications to attacker C2 infrastructure and prevent data exfiltration
- • Deploy multicloud visibility and control systems to detect anomalous WebDAV connections and suspicious scheduled task creation across hybrid environments
- • Enable threat detection and anomaly response capabilities to identify covert tools, remote access patterns, and baseline deviations in network behavior
- • Establish zero trust segmentation with identity-based policies to limit lateral movement and contain compromised endpoints from accessing sensitive resources
- • Deploy cloud firewall with URL filtering and AI-powered traffic analysis to block malicious domains and detect command and control communications



