< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom, Ukraine, Russia · 4 sources

started · updated

Microsoft reports expansion of Star Blizzard phishing and disruption of AI-driven EvilTokens

Microsoft has reported significant developments in cyber threats involving Russian-linked actors and AI-driven criminal services. The state-backed group Star Blizzard, also known as Callisto or ColdRiver, has expanded its phishing operations in 2026. Moving away from exclusively targeted spear-phishing, the group is now utilizing an automated mass-mailing platform and a new malware delivery method called RedFlick. This campaign has targeted over 100 organizations, primarily in the United States and the United Kingdom, including government agencies, NGOs, and financial institutions, with a notable focus on Ukrainian entities.

Separately, Microsoft and its partners have disrupted EvilTokens, a cybercrime service that leveraged artificial intelligence to facilitate email breaches and financial fraud. The platform used an AI chatbot to analyze stolen inboxes, map professional relationships, and draft convincing impersonation messages. Since its launch in February, EvilTokens was linked to more than 12,000 compromised inboxes across 10,000 organizations globally. In response, authorities seized 50 websites and disabled over 150 domains. Additionally, the Metropolitan Police Service in the United Kingdom arrested two men on September 11 in connection with the EvilTokens operation.

Entities

EvilTokens · Federal Security Service · Metropolitan Police Service · Microsoft · Star Blizzard · Ukraine · United States

Claims

What the coverage asserts, and how many sources carry each claim.