Star Blizzard shifts to automated RedFlick attacks against Ukraine-linked targets

2 min read
Source: BleepingComputer
Star Blizzard shifts to automated RedFlick attacks against Ukraine-linked targets
Photo: BleepingComputer
TL;DR

Russian state actor Star Blizzard has adopted a new malware delivery method called RedFlick to automate the installation of the CosmicPulse backdoor. This technique reduces the need for manual victim interaction compared to previous ClickFix campaigns. Microsoft reports that at least 13 large-scale phishing campaigns have impacted over 100 organizations, primarily in the US and UK, since January 2026.

Key points

  • Star Blizzard, attributed to Russia's FSB, has expanded operations from targeted spear-phishing to mass-mailing campaigns using compromised websites and free email providers.
  • The RedFlick technique uses a malicious LNK file disguised as a PDF to trigger a hidden command that downloads an MSI installer.
  • The installer creates three scheduled tasks masquerading as legitimate maintenance tools to evade detection and deploy the CosmicPulse backdoor.
  • Targets include Ukrainian individuals, international NGOs, think tanks, and governments that have supported Ukraine politically or financially.
  • Microsoft advises organizations to use phishing-resistant authentication, Conditional Access policies, and endpoint detection and response (EDR) solutions in block mode.

Background

Star Blizzard has been active since 2017, previously using ClickFix and WhatsApp for delivery. In October 2025, Google reported on the actor's COLDCOPY malware. The current RedFlick campaigns represent a significant evolution in tradecraft, moving toward automated, large-scale operations to improve compromise rates and evade detection.

How outlets are covering it

Microsoft and The Hacker News agree on the technical details of the RedFlick chain and the scale of the campaigns. Microsoft emphasizes the shift to compromised websites for sending emails, while The Hacker News highlights the use of steganography in some campaigns. BleepingComputer focuses on the automation aspect, noting that RedFlick requires only a single user interaction compared to the multiple steps needed for ClickFix. All sources confirm the targeting of Ukraine-related entities and the use of the CosmicPulse backdoor.

Why it matters

The shift to automated, large-scale phishing campaigns increases the risk of successful compromises for organizations in government, NGOs, and think tanks. The use of multiple scheduled tasks and decoy files makes detection more difficult, requiring robust endpoint protection and user awareness to mitigate the threat.

What to watch

Organizations should implement Microsoft's recommended defenses, including phishing-resistant authentication and EDR solutions. Microsoft will continue to notify targeted customers and provide hunting queries. The actor may continue to refine its techniques in response to public exposure and defensive measures.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer