INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Star Blizzard Refines Phishing and Malware Delivery with RedFlick
| 2026-09-30 03:35 CRITICAL HIGH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A Russia-linked advanced persistent threat (APT) actor, known as Star Blizzard, has significantly expanded its phishing and malware-delivery tactics since January 2026. The APT group, which was disrupted by Microsoft and US officials two years ago, has shifted its focus to targeting journalists, NGOs, government organizations, and individuals supporting Ukraine worldwide. Since March, campaigns have targeted users of the Ukrainian email provider [IOC HIDDEN • LOGIN REQUIRED], impersonating Ukrainian tax or other authorities. In addition, Star Blizzard has been detected in 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations globally. The APT group's tactics have evolved to include social engineering and Python-based attacks, with phishing emails often crafted to appear as internal communications originating from the targeted organization itself.
Technical Mitigations AI-generated
• Implement RedFlick detection and blocking to prevent the deployment of CosmicPulse backdoor.
• Utilize behavioral analysis tools to identify and flag suspicious scheduled tasks that may be indicative of RedFlick infections.
• Leverage machine learning-based email filtering solutions to detect and block large-scale phishing campaigns targeting NGOs, think tanks, and government organizations worldwide.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
et•••••.ca
st•••••.org
mu•••••.net
ru•••••.observer
cm•••••.exe
co•••••.exe
1f2096••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
9707a8••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dd98db••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
699e92••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
45.84.•••.•••
103.245.•••.•••
89.125.•••.•••
2.57.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
GCC
GCC
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
January 2026
Star Blizzard, a Russian state threat actor, has refined its phishing and malware delivery tactics using the RedFlick technique since January 2026.
Click on any entity below to view its context and source!
source_region
Russian Federation
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
tactic
Phishing
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
organisation
Microsoft
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
threat_actor
Star Blizzard
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
Sept. 29
Star Blizzard has refined its phishing and malware delivery with the RedFlick technique, targeting journalists, NGOs, and Russia experts supporting Ukraine.
Click on any entity below to view its context and source!
tactic
Phishing
Star Blizzard, active since 2017 and known for targeting journalists, nongovernmental organizations (NGOs), and Russia experts — particularly those supporting Ukraine — has since January demonstrated a key tactical change in its phishing initial-access method, Microsoft Threat Intelligence (MTI) revealed in
a blog post
on Sept. 29.
threat_actor
Star Blizzard
Star Blizzard, active since 2017 and known for targeting journalists, nongovernmental organizations (NGOs), and Russia experts — particularly those supporting Ukraine — has since January demonstrated a key tactical change in its phishing initial-access method, Microsoft Threat Intelligence (MTI) revealed in
a blog post
on Sept. 29.
target_region
Ukraine
Star Blizzard, active since 2017 and known for targeting journalists, nongovernmental organizations (NGOs), and Russia experts — particularly those supporting Ukraine — has since January demonstrated a key tactical change in its phishing initial-access method, Microsoft Threat Intelligence (MTI) revealed in
a blog post
on Sept. 29.
target_region
Russian Federation
Star Blizzard, active since 2017 and known for targeting journalists, nongovernmental organizations (NGOs), and Russia experts — particularly those supporting Ukraine — has since January demonstrated a key tactical change in its phishing initial-access method, Microsoft Threat Intelligence (MTI) revealed in
a blog post
on Sept. 29.
attribution
Microsoft Threat Intelligence
Star Blizzard, active since 2017 and known for targeting journalists, nongovernmental organizations (NGOs), and Russia experts — particularly those supporting Ukraine — has since January demonstrated a key tactical change in its phishing initial-access method, Microsoft Threat Intelligence (MTI) revealed in
a blog post
on Sept. 29.
2026/09/30
Threat actors used the RedFlick technique to refine phishing and malware delivery, starting an infection chain via Windows utilities such as conhost.exe and cmd.exe that creates scheduled tasks to execute malware.
Click on any entity below to view its context and source!
organisation
Microsoft
A Russia-linked advanced persistent threat (APT) actor that
was significantly disrupted
by Microsoft and US officials two years ago is casting a wider net than ever with its phishing and malware-delivery tactics.
organisation
APT
A Russia-linked advanced persistent threat (APT) actor that
was significantly disrupted
by Microsoft and US officials two years ago is casting a wider net than ever with its phishing and malware-delivery tactics.
threat_actor
Star Blizzard
IOC - Star Blizzard refines phishing and malware delivery with the RedFlick technique.
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net.
Undaunted, Star Blizzard has continued to evolve, with Microsoft detecting 13 distinct "large-scale
phishing campaigns
targeting primarily NGOs, think tanks, and government organizations worldwide" since January.
This change, combined with the actor's shift toward large-scale phishing operations during the same period, likely increases the APT's chance of success, Microsoft warned, which should put organizations typically in Star Blizzard's crosshairs on alert.
In the past, the actor primarily used phishing emails to steal login credentials from its victims and was the target of a 2024 joint operation by Microsoft and the Department of Justice to seize 41 of Star Blizzard's Internet domains.
Indeed, Star Blizzard has significantly widened the scale of its email attacks, sending hundreds of messages per campaign in contrast to its previous, carefully researched and narrowly focused spear-phishing operations.
Piyush Sharma, co-founder and CEO of security firm Tuskira, says the speed with which Star Blizzard is reducing its interaction with victims on its way to compromising them is notable, demonstrating rapid evolution and determination in the actor's latest
phishing attacks
.
Defending Against Changing Star Blizzard Tactics
Though
Star Blizzard
has changed its tactics, its overall phishing patterns remain the same, and Microsoft advised organizations to set their security defenses accordingly.
Latest Star Blizzard Activity
Star Blizzard, also referred to as
ColdRiver
and Callisto, is a subordinate to the Russian Federal Security Service Center (FSB) Center 18, according to the US Cybersecurity and Infrastructure Security Agency (CISA).
Furthermore, in new campaigns, Star Blizzard is showing off new capabilities previously unassociated with the actor, including steganography to conceal identifiers and the targeting of vulnerable Apple iOS devices to deploy the
DarkSword backdoor
, as
reported
by Proofpoint in March.
Star Blizzard in July demonstrated another infection chain that required little more than the victim opening a lure and used trusted Windows components to handle execution, persistence, and payload retrieval, according to Microsoft.
"As part of this evolution,
Star Blizzard
adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's
custom backdoor
, CosmicPulse," according to MTI's post.
Various RedFlick Infection Paths
RedFlick signals a major change to how Star Blizzard is targeting victims through email, Microsoft said.
Organizations also should continue with other general security mitigations to reduce the impact of a successful initial entry via Star Blizzard's attack chain, including using
endpoint detection and response
(EDR) in block mode to block malicious artifacts.
organisation
IOC -
IOC - Star Blizzard refines phishing and malware delivery with the RedFlick technique.
organisation
RedFlick
IOC - Star Blizzard refines phishing and malware delivery with the RedFlick technique.
"As part of this evolution,
Star Blizzard
adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's
custom backdoor
, CosmicPulse," according to MTI's post.
organisation
the Department of Justice
In the past, the actor primarily used phishing emails to steal login credentials from its victims and was the target of a 2024 joint operation by Microsoft and the Department of Justice to seize 41 of Star Blizzard's Internet domains.
organisation
Mass Disinformation
Related:
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
In campaigns observed by Microsoft, victims receive password-protected zip or RAR archives containing an LNK file disguised as a document, often a PDF.
organisation
RAR
Related:
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
In campaigns observed by Microsoft, victims receive password-protected zip or RAR archives containing an LNK file disguised as a document, often a PDF.
organisation
LNK
Related:
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
In campaigns observed by Microsoft, victims receive password-protected zip or RAR archives containing an LNK file disguised as a document, often a PDF.
organisation
PDF
Related:
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
In campaigns observed by Microsoft, victims receive password-protected zip or RAR archives containing an LNK file disguised as a document, often a PDF.
infrastructure
Ios
Furthermore, in new campaigns, Star Blizzard is showing off new capabilities previously unassociated with the actor, including steganography to conceal identifiers and the targeting of vulnerable Apple iOS devices to deploy the
DarkSword backdoor
, as
reported
by Proofpoint in March.
organisation
Apple
Furthermore, in new campaigns, Star Blizzard is showing off new capabilities previously unassociated with the actor, including steganography to conceal identifiers and the targeting of vulnerable Apple iOS devices to deploy the
DarkSword backdoor
, as
reported
by Proofpoint in March.
infrastructure
Windows
Star Blizzard in July demonstrated another infection chain that required little more than the victim opening a lure and used trusted Windows components to handle execution, persistence, and payload retrieval, according to Microsoft.
RedFlick is a malware delivery and persistence technique with various infection paths that all share a common thread: an effort to make malicious execution blend into normal Windows activity while reducing the amount of work required from the victim.
The LNK uses Windows utilities such as conhost.exe and cmd.exe to start the infection chain via an
MSI installer
that creates scheduled tasks to execute malware, reducing the manual steps required compared with the actor's earlier ClickFix campaigns.
organisation
CosmicPulse
"As part of this evolution,
Star Blizzard
adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's
custom backdoor
, CosmicPulse," according to MTI's post.
organisation
MTI
"As part of this evolution,
Star Blizzard
adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's
custom backdoor
, CosmicPulse," according to MTI's post.
organisation
EDR
Organizations also should continue with other general security mitigations to reduce the impact of a successful initial entry via Star Blizzard's attack chain, including using
endpoint detection and response
(EDR) in block mode to block malicious artifacts.
organisation
MSI
The LNK uses Windows utilities such as conhost.exe and cmd.exe to start the infection chain via an
MSI installer
that creates scheduled tasks to execute malware, reducing the manual steps required compared with the actor's earlier ClickFix campaigns.
organisation
ClickFix
In recent attacks, the nation-state actor has ditched its previous ClickFix strategy for a novel technique, allowing it to reach even more targets and evade detection.
organisation
CPL
This chain hid PowerShell payload data inside an apparently
legitimate PDF
, which eventually created scheduled tasks and ultimately launched the CPL-based CosmicPulse downloader with minimal user interaction.
organisation
Star Blizzards'
Tuskira's Sharma warns that
other threat groups
may attempt to copy Star Blizzards' RedFlick techniques going forward.
Tactical Metrics
Metrics
infrastructure
Ios
Affected Product
Click for context!
Furthermore, in new campaigns, Star Blizzard is showing off new capabilities previously unassociated with the actor, including steganography to conceal identifiers and the targeting of vulnerable Apple iOS devices to deploy the
DarkSword backdoor
, as
reported
by Proofpoint in March.
Metrics
infrastructure
Windows
Affected Product
RedFlick is a malware delivery and persistence technique with various infection paths that all share a common thread: an effort to make malicious execution blend into normal Windows activity while reducing the amount of work required from the victim.
The LNK uses Windows utilities such as conhost.exe and cmd.exe to start the infection chain via an
MSI installer
that creates scheduled tasks to execute malware, reducing the manual steps required compared with the actor's earlier ClickFix campaigns.
Star Blizzard in July demonstrated another infection chain that required little more than the victim opening a lure and used trusted Windows components to handle execution, persistence, and payload retrieval, according to Microsoft.
Intelligence Sources
Dark Reading
2026-09-30
AlienVault OTX
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:42
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
Microsoft
entity
5x
target region
Target Country
Ukraine
country
4x
timeline
Temporal Reference
January 2026
date
4x
attribution
Attributing Entity
Microsoft Threat Intelligence
authority
3x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
2x
source region
Origin Country
Russian Federation
country
2x
tactic
Cyber Operation Type
Phishing
tactic
2x
infrastructure
Affected Product
Ios
software
Contextual Telemetry
Context Block
4 METRICS
threat actor
APT Group
Star Blizzard
actor
industry
Targeted Sector
Government
sector
general metric
Distinct Scale Phishing Campaigns
13
distinct scale phishing campaigns
general metric
Justice
41
justice
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.