A Kremlin-linked espionage crew has swapped painstaking spear-phishing for bulk mail runs, according to Microsoft research published September 29.
The group, tracked as Star Blizzard and tied to Russia’s FSB, also answers to SEABORGIUM, Callisto Group, TA446 and COLDRIVER. Its newer campaigns fire tens to hundreds of messages at a time, a scale the company says the actor reached by adopting an automated mass-mailing platform.
The delivery chain carries a technique Microsoft calls RedFlick. It chains scheduled tasks to plant a backdoor named CosmicPulse, and the company says the whole flow needs only a single user interaction to take hold.
Lures lean on invitations to exclusive events, plus notices about tax audits, unpaid invoices and fines. Since January, Microsoft counted at least 13 large-scale campaigns aimed mainly at NGOs, think tanks and government bodies. More than 100 organizations, mostly in the United States and United Kingdom, have been touched.
Early waves focused on Ukraine before spreading outward. Microsoft reads that drift as a test run: the crew likely honed its tooling against Kyiv first, then widened the net to governments and nonprofits backing Ukraine.
Defenders should tighten rules on inbound event and finance-themed mail, watch for scheduled-task persistence, and treat any single risky click as a possible breach rather than a near miss.
