# Star Blizzard Targets US and UK Organizations

Microsoft reported at least 13 Star Blizzard phishing campaigns since January 2026, affecting more than 100 organizations, primarily in the United States and United Kingdom. The campaigns use the RedFlick technique, which leverages scheduled tasks to deliver and maintain the CosmicPulse backdoor with fewer user actions. For agencies and contractors, this creates a concrete risk to organizational systems and the procurement work, data, and services they support.

- **Why this matters:** Government agencies and contractors may be exposed to phishing-enabled compromise, making protection of contractor networks and government-related information a procurement and operational concern.
- Organizations should strengthen phishing-resistant authentication and endpoint controls, and improve detection of suspicious scheduled-task and script activity, as described in the signal.
- Contractors providing IT or cybersecurity services can use these attack methods to assess whether their existing authentication, endpoint, and monitoring capabilities address the risks highlighted by Microsoft.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 05, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- U.S. Department of Justice (DOJ)

### Sources
- [Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique](https://hackread.com/star-blizzard-organizations-phishing-redflick-technique) - Hackread