Russian Star Blizzard APT upgrades phishing and malware delivery with RedFlick technique

 

Russian Star Blizzard APT upgrades phishing and malware delivery with RedFlick technique

Russian state-linked threat actor, tracked as Star Blizzard, has changed its phishing and malware delivery tactics in 2026, using larger campaigns and a new technique Microsoft calls RedFlick.

Since January, Microsoft has observed Star Blizzard targeting Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments and financial organizations involved in supporting Ukraine. More than 100 organizations, mainly in the US and UK, have been affected.

The group is attributed by the US Cybersecurity and Infrastructure Security Agency (CISA) to Centre 18 of Russia's Federal Security Service (FSB).

RedFlick is designed to reduce the number of actions required from a victim. In past campaigns, Star Blizzard used ClickFix-based infection chains that required several user actions that led to installation of the CosmicPulse backdoor. RedFlick instead uses a single interaction to begin the infection process.

The attacks often start with a phishing email. If the recipient responds, a follow-up message is sent containing a password-protected RAR or ZIP archive. The password is provided as an image in the email. The archive contains files that begin the RedFlick infection chain.

Microsoft observed several versions of the technique, all of which include an LNK shortcut disguised as a PDF. When opened, the shortcut runs commands that download a Windows Installer (MSI) package from a remote server.

In a January campaign, a hidden script used SSH to download the installer. In a July version, the shortcut downloaded a PDF containing a hidden command designed to fetch the installer.

An April variant used the MSI package to create three scheduled tasks to send information to a command-and-control server, execute code remotely, and configure WebDAV, a Windows feature that can make a remote web location appear like a folder. The chain also used the Windows Control Panel executable (control.exe) to launch the next stage from the remote server.

The following stage is a downloader disguised as a Control Panel element. It installs a Python-based backdoor called CosmicPulse (NOROBOT or BAITSWITCH).

Interestingly, not all of the attacks leveraged the same payload. Microsoft observed a phishing campaign in March that sent a link to an iPhone exploit kit called DarkSword rather than the Windows-based CosmicPulse chain.


Back to the list