Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
What happened
The Russian state-backed hacking group Star Blizzard has expanded its phishing (messages that impersonate someone to obtain passwords or money) operations this year, using a new technique that makes it easier to infect victims with malware. The hacking group, known as Star Blizzard, has targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments and financial institutions that support Ukraine politically or financially.
In a report published Tuesday, Microsoft said the activity has affected more than 100 organizations, primarily in the U.S. Star Blizzard , also tracked as Callisto and ColdRiver, has previously been linked by Western governments to Russia’s Federal Security Service, or FSB.
The group has been active since at least 2017 and is known for targeting government agencies, NGOs and organizations involved in international affairs. Since the beginning of 2026, researchers have seen the hackers significantly expand their operations, moving beyond highly targeted spear-phishing attacks to campaigns involving tens or hundreds of emails at a time.
Microsoft has identified at least 13 such large-scale campaigns since January. Star Blizzard has also changed how it sends phishing messages.
Sources & evidence
- The Record Reporting source
Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters ↗
https://therecord.media/russia-hackers-ukraine-blizzard