INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Star Blizzard Refines Phishing and Malware Delivery with RedFlick

| 2026-09-30 03:35 CRITICAL HIGH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A Russia-linked advanced persistent threat (APT) actor, known as Star Blizzard, has significantly expanded its phishing and malware-delivery tactics since January 2026. The APT group, which was disrupted by Microsoft and US officials two years ago, has shifted its focus to targeting journalists, NGOs, government organizations, and individuals supporting Ukraine worldwide. Since March, campaigns have targeted users of the Ukrainian email provider [IOC HIDDEN • LOGIN REQUIRED], impersonating Ukrainian tax or other authorities. In addition, Star Blizzard has been detected in 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations globally. The APT group's tactics have evolved to include social engineering and Python-based attacks, with phishing emails often crafted to appear as internal communications originating from the targeted organization itself.
Technical Mitigations AI-generated
• Implement RedFlick detection and blocking to prevent the deployment of CosmicPulse backdoor. • Utilize behavioral analysis tools to identify and flag suspicious scheduled tasks that may be indicative of RedFlick infections. • Leverage machine learning-based email filtering solutions to detect and block large-scale phishing campaigns targeting NGOs, think tanks, and government organizations worldwide.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

et•••••.ca
st•••••.org
mu•••••.net
ru•••••.observer
cm•••••.exe
co•••••.exe
1f2096••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
9707a8••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dd98db••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
699e92••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
45.84.•••.•••
103.245.•••.•••
89.125.•••.•••
2.57.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
GCC GCC NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎January 2026
Star Blizzard, a Russian state threat actor, has refined its phishing and malware delivery tactics using the RedFlick technique since January 2026.
source_region Russian Federation
tactic Phishing
organisation Microsoft
threat_actor Star Blizzard
‎Sept. 29
Star Blizzard has refined its phishing and malware delivery with the RedFlick technique, targeting journalists, NGOs, and Russia experts supporting Ukraine.
tactic Phishing
threat_actor Star Blizzard
target_region Ukraine
target_region Russian Federation
attribution Microsoft Threat Intelligence
‎2026/09/30
Threat actors used the RedFlick technique to refine phishing and malware delivery, starting an infection chain via Windows utilities such as conhost.exe and cmd.exe that creates scheduled tasks to execute malware.
organisation Microsoft
organisation APT
threat_actor Star Blizzard
organisation IOC -
organisation RedFlick
organisation the Department of Justice
organisation Mass Disinformation
organisation RAR
organisation LNK
organisation PDF
infrastructure Ios
organisation Apple
infrastructure Windows
organisation CosmicPulse
organisation MTI
organisation EDR
organisation MSI
organisation ClickFix
organisation CPL
organisation Star Blizzards'
Tactical Metrics
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎Windows
Affected Product