Skip to content

Star Blizzard adopts RedFlick and CosmicPulse in 13 active FSB campaigns

2 min read
Share

Microsoft Threat Intelligence published analysis on September 29 confirming that Star Blizzard, the FSB Centre 18-linked threat actor previously tracked as SEABORGIUM and Callisto Group, has fully retired its LightShow toolkit. Two new malware families are now in active deployment across 13 confirmed campaigns targeting NATO-aligned organizations.

The new toolkit: RedFlick and CosmicPulse

RedFlick is a .NET backdoor engineered for persistent access and encrypted command-and-control communications. CosmicPulse is a multi-stage PowerShell loader chain that delivers secondary payloads after initial access is established. Together, they replace the LightShow infrastructure that defenders and researchers had documented across prior Star Blizzard campaigns.

The shift is operationally significant. LightShow was well-characterized, with published indicators of compromise and vendor detections broadly available. The move to RedFlick and CosmicPulse resets much of that detection coverage.

Campaign scope and target selection

MSTIC identified 13 active campaigns running at the time of the report. Targets include NATO-aligned foreign policy staff, international think tanks, non-governmental organizations focused on democracy and human rights issues, and journalists covering Eastern European affairs. More than 100 organizations were targeted across the tracked campaign period. The geographic focus remains consistent with prior Star Blizzard operations: North America, the United Kingdom, and EU member states.

The group's continued focus on civil society and foreign policy institutions reflects the FSB's long-term intelligence collection mandate rather than financially motivated activity. Star Blizzard is not looking for ransomware leverage; it is seeking persistent access for strategic intelligence purposes.

What defenders should do

Organizations that previously detected or mitigated Star Blizzard intrusions using LightShow-based indicators should treat those indicators as stale. RedFlick and CosmicPulse bring different network signatures, persistence mechanisms, and staging infrastructure. MSTIC has published updated indicators of compromise alongside the September 29 report; update detections from that source directly.

Defenders in targeted sectors, particularly those supporting NATO foreign policy dialogue, democratic governance work, or journalism on Russia and Eastern Europe, should prioritize phishing-resistant authentication, email gateway hardening, and awareness training for staff who regularly communicate with external contacts in the policy space. Initial access for this group consistently arrives via spearphishing.