Executive Summary
Since January 2026, Russian state-sponsored threat actor Star Blizzard (FSB Centre 18) has significantly evolved their cyber espionage operations by implementing the RedFlick malware delivery technique and transitioning from targeted spear-phishing to large-scale phishing campaigns. The actor deployed CosmicPulse backdoor through sophisticated infection chains involving VHDX files, scheduled tasks, and PDF-concealed payloads, targeting over 100 organizations including Ukrainian institutions, international NGOs, Western think tanks, and government entities supporting Ukraine. RedFlick represents a notable operational shift that reduces required user interactions while improving scalability and detection evasion capabilities.
This campaign demonstrates the accelerating sophistication of nation-state actors adapting their tactics in response to geopolitical conflicts, with Russian APT groups increasingly automating and scaling their operations to maximize intelligence collection efficiency against Western policy institutions.
Why This Matters Now
Nation-state actors are rapidly evolving their attack methodologies to bypass traditional security controls, with Russian APT groups leading the charge in developing automated, scalable espionage capabilities that target critical policy-making institutions during ongoing geopolitical tensions.
Attack Path Analysis
Star Blizzard conducted large-scale phishing campaigns using compromised websites and RedFlick technique to deliver CosmicPulse backdoor. The attack progressed from initial email compromise through scheduled task persistence, enabling command and control for ongoing espionage operations against Ukrainian and Western organizations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Large-scale phishing campaigns targeting NGOs, think tanks, and government organizations using compromised websites to create sender accounts. Victims received password-protected archives containing VHDX files or malicious LNK files disguised as PDFs.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Scheduled Task/Job: Scheduled Task
Command and Scripting Interpreter: PowerShell
Process Injection
Ingress Tool Transfer
Obfuscated Files or Information
Software Discovery: Security Software Discovery
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Training
Control ID: 12.10.4
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Network and Environment Protection
Control ID: 4.2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Identity Management
Control ID: A.5.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Primary target of Star Blizzard nation-state espionage campaigns using RedFlick malware delivery, requiring enhanced zero trust segmentation and egress security controls.
Non-Profit/Volunteering
Extensively targeted by Russian FSB phishing operations impersonating legitimate organizations, necessitating encrypted traffic protection and multicloud visibility for donor security.
Higher Education/Acadamia
Think tanks and academic institutions face sophisticated social engineering attacks via compromised websites, demanding inline IPS and threat detection capabilities.
Financial Services
International financial organizations targeted through steganography-concealed malware requiring east-west traffic security and anomaly response systems for compliance protection.
Sources
- Star Blizzard refines phishing and malware delivery with the RedFlick techniquehttps://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/Verified
- CISA Cybersecurity Advisory AA23-341Ahttps://www.cisa.gov/news-events/cybersecurity-advisories/aa23-341aVerified
- Google Threat Intelligence - New malware from Russia COLDRIVERhttps://cloud.google.com/blog/topics/threat-intelligence/new-malware-russia-coldriverVerified
- Digital Security Lab Ukraine - Spearphishing via fake URC 2026 invitations targets Ukrainian CSOshttps://dslua.org/publications/spearphishing-via-fake-urc-2026-invitations-targets-ukrainian-csos/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained Star Blizzard's lateral movement capabilities and reduced their operational reach across targeted organizations. The segmentation controls would likely have limited blast radius and contained the CosmicPulse backdoor's network access.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise through phishing would likely still succeed, but CNSF visibility controls could have provided earlier detection of anomalous network behaviors and suspicious file execution patterns.
Control: Zero Trust Segmentation
Mitigation: Scheduled task creation would likely still occur, but segmentation policies could have limited the tasks' network access scope and reduced their ability to communicate with external infrastructure.
Control: East-West Traffic Security
Mitigation: WebDAV-based lateral movement attempts would likely have been constrained by east-west traffic controls, reducing the attacker's ability to access remote network shares and pivot between systems.
Control: Multicloud Visibility & Control
Mitigation: C2 communications would likely have been detected and potentially blocked through centralized visibility controls, reducing the backdoor's ability to maintain persistent communication channels with external servers.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely have been constrained by egress controls, limiting the volume and frequency of information that could be transmitted to external C2 infrastructure.
While complete prevention of espionage impact would be unlikely, the overall blast radius and data exposure would have been substantially reduced through network segmentation and access controls.
Impact at a Glance
Affected Business Functions
- International Policy Operations
- Diplomatic Communications
- Research and Analysis
- Financial Operations
Estimated downtime: 7 days
Estimated loss: N/A
Potential exposure of sensitive diplomatic communications, policy documents, financial records of Ukrainian support organizations, think tank research materials, and government correspondence across over 100 targeted organizations in the US and UK
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege access controls to prevent lateral movement between network resources and limit the scope of compromise from initial phishing attacks
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound communications to actor-controlled C2 infrastructure and prevent data exfiltration through strict FQDN filtering
- • Enable Multicloud Visibility & Control to detect anomalous WebDAV traffic patterns, suspicious scheduled task creation, and repeated malformed requests that indicate RedFlick activity
- • Activate Threat Detection & Anomaly Response capabilities to identify CosmicPulse backdoor communications and baseline normal system behavior to catch registration beaconing activities
- • Strengthen email security with Cloud Firewall (ACF) URL filtering and inline IPS inspection to block malicious attachments and prevent initial compromise through phishing campaigns



