Star Blizzard shifts to automated RedFlick attacks against Ukraine-linked targets

Russian state actor Star Blizzard has adopted a new malware delivery method called RedFlick to automate the installation of the CosmicPulse backdoor. This technique reduces the need for manual victim interaction compared to previous ClickFix campaigns. Microsoft reports that at least 13 large-scale phishing campaigns have impacted over 100 organizations, primarily in the US and UK, since January 2026.
Key points
- Star Blizzard, attributed to Russia's FSB, has expanded operations from targeted spear-phishing to mass-mailing campaigns using compromised websites and free email providers.
- The RedFlick technique uses a malicious LNK file disguised as a PDF to trigger a hidden command that downloads an MSI installer.
- The installer creates three scheduled tasks masquerading as legitimate maintenance tools to evade detection and deploy the CosmicPulse backdoor.
- Targets include Ukrainian individuals, international NGOs, think tanks, and governments that have supported Ukraine politically or financially.
- Microsoft advises organizations to use phishing-resistant authentication, Conditional Access policies, and endpoint detection and response (EDR) solutions in block mode.
Background
Star Blizzard has been active since 2017, previously using ClickFix and WhatsApp for delivery. In October 2025, Google reported on the actor's COLDCOPY malware. The current RedFlick campaigns represent a significant evolution in tradecraft, moving toward automated, large-scale operations to improve compromise rates and evade detection.
How outlets are covering it
Microsoft and The Hacker News agree on the technical details of the RedFlick chain and the scale of the campaigns. Microsoft emphasizes the shift to compromised websites for sending emails, while The Hacker News highlights the use of steganography in some campaigns. BleepingComputer focuses on the automation aspect, noting that RedFlick requires only a single user interaction compared to the multiple steps needed for ClickFix. All sources confirm the targeting of Ukraine-related entities and the use of the CosmicPulse backdoor.
Why it matters
The shift to automated, large-scale phishing campaigns increases the risk of successful compromises for organizations in government, NGOs, and think tanks. The use of multiple scheduled tasks and decoy files makes detection more difficult, requiring robust endpoint protection and user awareness to mitigate the threat.
What to watch
Organizations should implement Microsoft's recommended defenses, including phishing-resistant authentication and EDR solutions. Microsoft will continue to notify targeted customers and provide hunting queries. The actor may continue to refine its techniques in response to public exposure and defensive measures.
- Russian state hackers use new RedFlick technique to push malware BleepingComputer
- Star Blizzard refines phishing and malware delivery with the RedFlick technique Microsoft
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor The Hacker News
- Star Blizzard, Cloudflare CA, GPT-6.1 scuttled LinkedIn
- Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters The Record from Recorded Future News
Want the full story? Read the original reporting
Read on BleepingComputer