Russian state-linked Star Blizzard (also tracked as COLDRIVER) expanded its espionage phishing activity between January and August 2026, targeting more than 100 organizations, principally in the United States and United Kingdom. Targets included Ukrainian individuals and institutions, governments, NGOs, think tanks, financial organizations, academics, media, and diplomatic entities involved in Ukraine policy or support. The actor abused compromised cPanel- and WordPress-hosted sites to create sender accounts, then sent password-protected archives to recipients who engaged with initial lures.
Microsoft identified the actor’s RedFlick technique as a low-interaction delivery chain that uses VHDX/LNK files, MSI packages, Control Panel applets, PowerShell, and scheduled tasks to deploy the Python-based CosmicPulse backdoor. Persistence tasks impersonate network components, beacon host details, enable WebDAV remote execution, and retrieve a CosmicPulse downloader; July activity also hid Base64-encoded PowerShell payloads in PDFs. This development follows COLDRIVER’s 2025 rollout of the obfuscated PowerShell backdoor MAYBEROBOT (also called SIMPLEFIX), which replaced the Python-dependent YESROBOT and supported remote command execution and payload retrieval, indicating continued investment in adaptable malware delivery and evasion.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
A mid-August 2026 Star Blizzard campaign used steganography to conceal identifiers and sent unique ZIP attachments to individual targets.
In July 2026, Star Blizzard used nested password-protected RAR-in-ZIP archives containing an LNK that downloaded a PDF from actor infrastructure. The PDF concealed a Base64-encoded PowerShell command intended to download and install another MSI file.
By April 2026, RedFlick MSI installers created scheduled tasks named Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor. The tasks supported host reconnaissance, WebDAV-enabled remote resource access, and retrieval and execution of next-stage payloads.
Beginning in March 2026, Star Blizzard expanded targeting beyond Ukraine, using purported conference and closed-door event invitations from think tanks or NGOs as lures. It also began using sender accounts created on compromised CPanel- and WordPress-hosted websites, shifting toward campaigns that sent tens to hundreds of messages.
In mid-January 2026, Star Blizzard sent password-protected ZIP archives containing malicious VHDX files. The VHDX chain used a disguised LNK, BAT script, conhost.exe, SSH with PermitLocalCommand, and an MSI installer to create scheduled tasks and deploy the CosmicPulse/NOROBOT downloader.
Beginning in January 2026, Star Blizzard conducted large-scale phishing campaigns, initially using tax-audit and fine-payment lures impersonating Ukrainian authorities against Ukr.net users. Microsoft reported at least 13 campaigns from January onward.
From June through September 2025, COLDRIVER iterated on NOROBOT and its delivery chain, rotating infrastructure and changing file names, paths, DLL names, exports, cryptographic-key collection, and intermediate stages to evade detection. The final MAYBEROBOT backdoor remained unchanged during these delivery-chain changes.
In early June 2025, Google Threat Intelligence Group observed COLDRIVER delivering a simplified NOROBOT downloader that established logon-script persistence and downloaded the PowerShell backdoor MAYBEROBOT, also known as SIMPLEFIX. GTIG assessed MAYBEROBOT was intended to replace the Python-dependent YESROBOT backdoor.
Google added identified COLDRIVER-related malicious websites, domains, and files to Safe Browsing and sent government-backed attacker alerts to targeted Gmail and Workspace users.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourcecloud.google.com
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.