In This Article
In August 2026, employees of an international financial organization received an email titled "Payment Advice Note from 06.08.2026." It carried a password-protected ZIP file, and each recipient got a different one. Inside were the files that start a chain Microsoft calls RedFlick, built to end with a backdoor on the recipient's computer.
The sender was Star Blizzard, a Russian state threat actor. On September 29, 2026, Microsoft Threat Intelligence published a report on how the group changed its methods this year.
Star Blizzard added large phishing campaigns, tens to hundreds of messages each, to the targeted spear phishing attacks it's known for. It began sending from accounts on hijacked websites. And it adopted an install chain that needs a single action from the victim.
Microsoft's target list starts with Ukrainian individuals and institutions. It continues with international nongovernmental organizations (NGOs), think tanks, and governments, and ends with "financial institutions that have supported Ukraine politically or financially." Its list of those most at risk is shorter: primarily government, NGOs, and think tanks adjacent to Ukraine policy or support.
For a community bank, credit union, or mortgage company, the value of the report is the tradecraft. A payment-themed lure, mail made to look internal, an archive whose password arrives as a picture, and a one-step install all test the same email and endpoint controls every institution runs. Most of the defenses Microsoft recommends are settings in Microsoft Defender and Microsoft 365.
What Star Blizzard changed in 2026
Star Blizzard is a Russian espionage group that has phished its targets for years. In 2026 it changed three things: how many people it emails, where the mail comes from, and how much a victim has to do before the backdoor installs. In December 2023, cybersecurity agencies from the United States, the United Kingdom, Canada, Australia, and New Zealand published a joint advisory on the group. They assessed that it "is almost certainly subordinate to the Russian Federal Security Service (FSB) Centre 18."
Microsoft formerly called it SEABORGIUM, and other researchers know it as COLDRIVER and Callisto Group. Its classic method was patient impersonation: an email posing as someone the target knows, a reply, then a follow-up link to a site built to steal credentials. Microsoft's report traces how that method grew in 2026. The timeline below uses the campaigns and subject lines Microsoft published.
Fake tax audit and fine notices go to users of the Ukrainian email provider Ukr.net. In the January campaign, a password-protected ZIP holds a virtual disk with a shortcut file disguised as a PDF. Opening it pulls down an installer that creates a scheduled task, a Windows job that runs on its own.
Campaigns move beyond Ukraine, mostly as invitations to conferences and events presented as coming from think tanks and NGOs. The group starts sending from accounts it created on compromised cPanel and WordPress websites.
"Closed-Door Online Session on Global Capital Allocation & M&A" goes to international financial organizations and researchers. The installer now creates three scheduled tasks named like ordinary network components.
A shortcut file downloads a PDF from the attacker's server, and a hidden, encoded command inside it fetches the next installer.
Employees of an international financial organization receive a payment notice with a ZIP file unique to each recipient.
Microsoft counted at least 13 distinct large-scale campaigns since January. It says the jump in volume likely reflects a mass-mailing platform. Most 2026 lures were invitations to conferences and closed-door discussions. Four were about money: a tax audit, a fine, an investment session, and a payment notice.
Volume changes the lures. A spear-phishing email is written for one person. A campaign of hundreds needs lures that work on many people at once, like the four money-themed ones above. Those are subjects a treasury analyst, an accounts payable clerk, or a loan officer opens every week.
How a RedFlick phishing email works
In the invitation campaigns, the sequence Microsoft calls typical asks the recipient for one reply and one action. The tax, fine, and payment notices sent the archive to every target. Either way, everything after the recipient opens the file runs on its own.
An email, usually with no attachment, from a name the recipient knows or styled as internal mail, invites a reply.
Only people who respond receive the next message.
A follow-up carries a password-protected RAR or ZIP file. The password is a picture in the email.
Inside is a shortcut file disguised as a PDF. Opening it starts the chain.
An installer creates scheduled tasks that fetch CosmicPulse, a backdoor written in Python.
By April, Microsoft reports, the installer created three scheduled tasks "masquerading as legitimate network components": Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor. The first one sends the computer or network name and the username to the attacker's server. The third uses control.exe, a normal Windows program, to run the next stage from the attacker's server. In at least one incident, Microsoft saw the first or third task deploy CosmicPulse on an infected machine.
The single action is the change that matters most. Microsoft says the group's earlier ClickFix chains, the technique our ClickFix infostealer briefing explains, "required victims to complete multiple actions" before the backdoor could be installed. By contrast, "the RedFlick infection flow only requires a single user interaction." Every step the attacker removes is one less chance for a careful employee to stop and ask.
Who reads your Defender alerts when a scheduled task appears at 2 a.m.?
Microsoft has already named the detections for this campaign. Guardian MxDR monitors alerts from Microsoft Defender, Entra ID, and Purview around the clock for credit unions, banks, and mortgage companies.
Four signs your staff can spot
Microsoft's report describes patterns users can still watch for, even as Star Blizzard changes its tools. Four of them fit on one slide in your next security awareness session.
The name is in the wrong place
The sender shows a real person and organization, but the organization's name appears in the username, the part before the @. The domain after the @ belongs to an unrelated website or a free mail service.
The first email asks only for a reply
Initial contact usually carries no attachment. The file arrives after someone answers.
The password is a picture
The follow-up brings a password-protected RAR or ZIP file, and the password appears as an image in the message.
It looks like it came from inside
Microsoft says the emails were often crafted to look like internal communications, sent to several people in the same organization.
Microsoft's advice for a doubtful message is simple. Contact the person who supposedly sent it "using a previously established and trusted contact method such as known email address or phone number." That's the same call-back habit your wire room already uses for a changed payment instruction, extended to any unexpected archive.
Filters carry the rest of the load. Our guide to the Defender for Office 365 anti-phishing configuration examiners expect walks through the email policies that sit in front of your staff.
Seven Microsoft 365 and Defender settings to check
Microsoft lists the defenses for this campaign in its report. These seven, built on that list and Microsoft's product documentation, are the ones a bank, credit union, or mortgage company can check in its own Microsoft 365 tenant this week. Start with email, because every RedFlick chain begins with a message. ABT's free Microsoft 365 Security Assessment reports your Safe Links and Safe Attachments status as part of its email review.
Safe Attachments opens attachments in a virtual environment before delivery, a process Microsoft calls detonation. It is part of Microsoft Defender for Office 365 Plan 1, which Microsoft 365 Business Premium includes.
Safe Attachments can't fully scan or detonate a password-protected file unless the password is available, for example in the email body. A setting that Microsoft began rolling out worldwide in August 2026 (message center post MC1440701) quarantines those messages until someone releases them, and it stays off until an administrator turns it on.
Safe Links rewrites links in inbound mail and checks them again when someone clicks, in email, Teams, and supported Office apps.
It pulls malicious messages out of cloud mailboxes after delivery, when new threat intelligence identifies them.
Attack surface reduction rules target risky software behavior on Windows devices that attackers commonly exploit through malware. Microsoft's report names two: "Block executable files from running unless they meet a prevalence, age, or trusted list criterion" and "Block execution of potentially obfuscated scripts." Both need Microsoft Defender Antivirus with cloud-delivered protection.
Microsoft lists these first: phishing-resistant authentication methods and Conditional Access policies that lock down account access. The report notes Star Blizzard's Evilginx spear-phishing operations continued throughout 2026, alongside RedFlick.
Search Microsoft Defender for Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse, and Backdoor:Python/CosmicPulse. Institutions licensed for Microsoft Defender for Endpoint Plan 2, which includes advanced hunting, can also run Microsoft's query for the three scheduled task names.
Items one and two work as a pair. The report says Star Blizzard sends the archive password as an image. Microsoft's Safe Attachments documentation says a password-protected attachment can be fully scanned only when the password is available, for example extracted from the email body.
When Safe Attachments can't open a password-protected attachment, the setting "Block messages containing encrypted attachments that could not be scanned" holds the message in quarantine until an admin or the recipient releases it. Microsoft documents that the setting supports messages where a single password unlocks the attachments. The setting appears once Block is the unknown malware response. Microsoft uses "encrypted" here to mean password-protected, so email encrypted with Microsoft Purview Message Encryption, S/MIME, or Rights Management is outside the setting.
Lenders receive legitimate password-protected closing documents all the time, so treat this as a decision with a pilot group. Our article on Defender's password-protected attachment quarantine covers how to roll it out without stalling a closing.
For item five, Microsoft's attack surface reduction reference records an audited event for each rule, so you can run both rules in audit mode first and see which business applications would trip them. For item six, our guide to phishing-resistant multifactor authentication (MFA) for financial institutions covers passkeys, FIDO2 security keys, and what examiners now ask about them.
Two more items from Microsoft's list apply to specific setups. If a non-Microsoft antivirus product is your primary one, look at endpoint detection and response (EDR) in block mode. It lets Defender for Endpoint block malicious artifacts even when your primary antivirus misses them, and Microsoft makes it available in Defender for Endpoint Plan 2. And because the January chain used SSH, the Secure Shell remote connection protocol, to fetch its installer, Microsoft suggests restricting outbound SSH connections to external networks where there's no business need.
Microsoft's recommendations for this campaign fall into two groups. The first is configuration, set once and checked for changes: Safe Attachments, Safe Links, zero-hour auto purge, attack surface reduction rules, and Conditional Access. The second is attention: Microsoft named the detections for RedFlick and CosmicPulse and wrote advanced hunting queries for the delivery chain and the scheduled tasks, and each one pays off only when someone reads the result. Defender generates the signals, but something has to act on them, including at 2 in the morning when a two-person IT team is asleep.
If a search does turn up one of the task names or detections, treat it as an incident. With Guardian MxDR, ABT engineers trace the attack path, determine scope, contain the threat, and write the post-incident documentation. Our Microsoft 365 incident response plan guide lays out the decisions your institution makes in the first hours: who declares the incident, what evidence to preserve, and who contacts your regulator.
What examiners expect: training and monitoring
The federal standards speak in general terms. They call for training and for monitoring, and they leave the tools to you. Here's where each kind of institution finds that language:
- Banks: the Interagency Guidelines Establishing Information Security Standards tell each institution to "Train staff to implement the institution's information security program." Each federal banking agency adopted the same Guidelines; the Federal Deposit Insurance Corporation (FDIC) version is in Title 12 of the Code of Federal Regulations (12 CFR Part 364, Appendix B). The Guidelines also list "Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into customer information systems" among the measures each institution must consider.
- Federally insured credit unions: the National Credit Union Administration's (NCUA's) guidelines at 12 CFR Part 748, Appendix A carry the parallel instruction to train staff to implement the credit union's information security program. They also carry parallel monitoring language for member information systems.
- Mortgage companies and other lenders under the Federal Trade Commission's (FTC's) jurisdiction: the FTC Safeguards Rule goes further on training, as quoted below. Our guide to the FTC Safeguards Rule and Microsoft 365 for mortgage lenders covers the rest of the rule.
The FTC's wording, in 16 CFR 314.4(e)(1), is the most specific of the three, because it ties training to the risk assessment:
Providing your personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment;
A campaign like this one is the kind of risk that sentence anticipates. A new lure style, the payment notice with a password-protected archive, belongs in the risk assessment, and training should show staff what it looks like before they meet it. Microsoft's own attack simulation training, part of Defender for Office 365 Plan 2 and Microsoft 365 E5, includes a Malware Attachment technique, so a simulation can test how staff handle attachments as well as links.
Monitoring follows the same logic. The detections and hunting queries Microsoft published help only when someone reviews them, and a record of that review is what an examiner can check.
How ABT helps financial institutions
ABT is a Tier-1 Microsoft Cloud Solution Provider that has served more than 750 financial institutions over 25 years, and it manages Microsoft 365 tenants for credit unions, banks, and mortgage companies. Four of its services map to the defenses in this article.
M365 Guardian hardens the Microsoft 365 tenant, and every Guardian level includes Microsoft Defender for Office 365 configuration as part of that baseline. For the people side, M365 Guardian Attack Simulation & Training runs realistic phishing simulations, measures how aware your staff are today, and tracks how their behavior changes over time.
To see where your own settings stand, start with ABT's free Microsoft 365 Security Assessment. Its email review covers anti-phishing policies, Defender for Office 365 settings, and the status of Safe Links and Safe Attachments, alongside identity, data, devices, sharing, and compliance. It's free for any financial institution running Microsoft 365 and connects through a read-only integration. Most assessments finish within two weeks.
Settings are one part of Microsoft's list; the other is someone reading the alerts. Guardian MxDR, ABT's managed detection and response service, monitors alerts from Microsoft Defender, Entra ID, and Purview around the clock. That includes the email threats Defender for Office 365 reports, such as malware attachments and impersonation attempts. When an alert is real, ABT engineers trace which accounts are affected, contain the threat, and document what happened.
Put ABT engineers on your Microsoft Defender alerts
With Guardian MxDR, ABT provides:
- Around-the-clock monitoring of Microsoft Defender, Entra ID, and Purview alerts
- Investigation of affected accounts, lateral movement, and data exposure
- Containment through account isolation, password resets, and Conditional Access tightening
- Post-incident documentation
Frequently Asked Questions
Star Blizzard, formerly called SEABORGIUM and also known as COLDRIVER and Callisto Group, is a Russian state threat actor focused on espionage through phishing. A December 2023 joint advisory from US, UK, Canadian, Australian, and New Zealand cybersecurity agencies assessed that it is almost certainly subordinate to the Russian Federal Security Service's Centre 18.
RedFlick is Microsoft's name for Star Blizzard's 2026 malware delivery method. A password-protected archive holds a shortcut file disguised as a PDF, and opening it runs an installer that creates scheduled tasks, which fetch the CosmicPulse backdoor. Microsoft says the flow needs a single user interaction, where the group's earlier ClickFix chains needed several.
Microsoft's Star Blizzard report puts financial institutions on the target list when they have supported Ukraine politically or financially. The group's investment-session and payment-notice lures went to international financial organizations, and Microsoft's most-at-risk list is primarily government, NGOs, and think tanks adjacent to Ukraine policy or support. For community banks, credit unions, and mortgage companies, the lesson is the techniques.
Safe Attachments in Microsoft Defender for Office 365 cannot fully scan a password-protected attachment unless the password is available. With Block set as the unknown malware response, an administrator can turn on a setting that quarantines those messages until an admin or the recipient releases them. The setting began rolling out in August 2026 and is off by default.
Search Microsoft Defender for the detections Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse, and Backdoor:Python/CosmicPulse. Institutions licensed for Microsoft Defender for Endpoint Plan 2, which includes advanced hunting, can also run Microsoft's query for scheduled tasks named Internet Quality Test Connection, Network Configuration Manager, or System Health Monitor. Treat any match as an incident and follow your response plan.
The Interagency Guidelines and NCUA Part 748 tell institutions to train staff to implement the information security program. The FTC Safeguards Rule, which covers mortgage companies and other lenders under the FTC's jurisdiction, requires security awareness training updated as necessary to reflect risks identified by the risk assessment. A new phishing lure style belongs in that update.