started · updated
Microsoft reports expansion of Star Blizzard phishing and disruption of AI-driven EvilTokens
Microsoft has reported significant developments in cyber threats involving Russian-linked actors and AI-driven criminal services. The state-backed group Star Blizzard, also known as Callisto or ColdRiver, has expanded its phishing operations in 2026. Moving away from exclusively targeted spear-phishing, the group is now utilizing an automated mass-mailing platform and a new malware delivery method called RedFlick. This campaign has targeted over 100 organizations, primarily in the United States and the United Kingdom, including government agencies, NGOs, and financial institutions, with a notable focus on Ukrainian entities.
Separately, Microsoft and its partners have disrupted EvilTokens, a cybercrime service that leveraged artificial intelligence to facilitate email breaches and financial fraud. The platform used an AI chatbot to analyze stolen inboxes, map professional relationships, and draft convincing impersonation messages. Since its launch in February, EvilTokens was linked to more than 12,000 compromised inboxes across 10,000 organizations globally. In response, authorities seized 50 websites and disabled over 150 domains. Additionally, the Metropolitan Police Service in the United Kingdom arrested two men on September 11 in connection with the EvilTokens operation.
Entities
EvilTokens · Federal Security Service · Metropolitan Police Service · Microsoft · Star Blizzard · Ukraine · United States
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] Star Blizzard is using a new mass-mailing platform and an updated malware delivery method called RedFlick. www.archynewsy.com · cyberscoop.com
- [● 2 SOURCES] Microsoft reported that the Russian state-backed hacking group Star Blizzard expanded its phishing operations in 2026. www.archynewsy.com · cyberscoop.com
- [● 2 SOURCES] Microsoft and its partners seized 50 websites and disabled over 150 domains used by EvilTokens. campustechnology.com · www.datasecuritybreach.fr
- [● 2 SOURCES] EvilTokens was linked to more than 12,000 compromised inboxes across over 10,000 organizations globally. campustechnology.com · www.datasecuritybreach.fr
- [● 2 SOURCES] The Metropolitan Police Service arrested two men on September 11 in connection with the EvilTokens operation. campustechnology.com · www.datasecuritybreach.fr
- [○ 1 SOURCE] The group Star Blizzard is also tracked by researchers as Callisto and ColdRiver. www.archynewsy.com
- [● 2 SOURCES] Microsoft disrupted EvilTokens, a cybercrime service that utilized AI to facilitate email account breaches. campustechnology.com · www.datasecuritybreach.fr
- [● 2 SOURCES] The Star Blizzard campaign has targeted more than 100 organizations, primarily in the United States and the United Kingdom. www.archynewsy.com · cyberscoop.com