The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Russian state-sponsored threat actor Star Blizzard (linked to FSB Center 18) conducted sophisticated phishing campaigns throughout 2026, targeting over 100 organizations primarily in the U.S. and U.K. with fake event invitations. The group employed a new technique called RedFlick to deploy CosmicPulse backdoors through compromised WordPress and cPanel websites, using scheduled tasks to maintain persistence on Windows systems. At least one confirmed infection occurred among organizations tied to Ukraine policy and support.

This campaign represents a significant evolution in state-sponsored cyber espionage tactics, demonstrating increased sophistication in social engineering and malware delivery methods. The targeting of Ukraine-related entities amid ongoing geopolitical tensions highlights the persistent threat to critical infrastructure and policy organizations.

Why This Matters Now

State-sponsored groups are rapidly evolving their attack methods, with Star Blizzard's RedFlick technique representing a new standard for persistence and evasion that other threat actors will likely adopt, requiring immediate updates to detection and prevention strategies.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

RedFlick is a malware delivery method that uses Windows scheduled tasks to install the CosmicPulse backdoor, triggered by disguised LNK files that appear as PDFs but execute malicious commands.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of Star Blizzard's CosmicPulse campaign by constraining lateral movement and limiting access to sensitive workloads through microsegmentation. The comprehensive east-west traffic enforcement and controlled egress policies could have significantly reduced attacker reach across the 100+ targeted organizations.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial payload execution may have been constrained through workload isolation, limiting the scope of compromise to individual segments rather than broad network access

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation impact would likely be reduced through microsegmentation policies that limit cross-workload access even with elevated system privileges

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between workloads would likely be significantly constrained through granular east-west traffic policies that restrict inter-segment communication paths

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control communications would likely be reduced through comprehensive visibility across cloud environments and granular access controls that limit external connectivity

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration scope would likely be constrained through controlled egress policies that limit outbound data flows and restrict unauthorized external communications

Impact (Mitigations)

Overall campaign impact would likely be significantly reduced with compromised assets contained within specific network segments and limited cross-organizational reach

Impact at a Glance

Affected Business Functions

  • Government Policy Development
  • International Relations
  • Research and Analysis
  • Stakeholder Communications
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive government communications, policy documents, research data, and stakeholder contact information from over 100 targeted organizations, primarily think tanks, NGOs, and government bodies focused on Ukraine policy. The FSB-affiliated threat actor likely accessed email credentials and session tokens to facilitate ongoing intelligence collection operations.

Recommended Actions

  • • Implement egress security and policy enforcement to block unauthorized outbound communications to attacker C2 infrastructure and prevent data exfiltration
  • • Deploy multicloud visibility and control systems to detect anomalous WebDAV connections and suspicious scheduled task creation across hybrid environments
  • • Enable threat detection and anomaly response capabilities to identify covert tools, remote access patterns, and baseline deviations in network behavior
  • • Establish zero trust segmentation with identity-based policies to limit lateral movement and contain compromised endpoints from accessing sensitive resources
  • • Deploy cloud firewall with URL filtering and AI-powered traffic analysis to block malicious domains and detect command and control communications

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image