INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Star Blizzard Utilizes RedFlick Technique for Phishing and Malware Delivery
| 2026-09-29 15:56 CRITICAL HIGH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Microsoft has identified a significant shift in the tactics, techniques, and procedures (TTPs) of Russian state-sponsored Advanced Persistent Threat (APT) group Star Blizzard. Since January 2026, Star Blizzard has evolved its detection evasion capabilities through large-scale phishing campaigns, compromised website accounts, and a novel malware delivery technique dubbed "RedFlick." These changes represent a notable shift in the actor's operational tradecraft and support ongoing cyberespionage activity targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy. The RedFlick technique has been used to refine phishing and malware delivery, allowing Star Blizzard to evade detection more effectively. This update highlights the evolving threat landscape and underscores the importance of continued vigilance in detecting and mitigating cyber threats from state-sponsored actors.
Technical Mitigations AI-generated
• Implementing behavioral analysis and machine learning-based detection to identify anomalies in user interactions that may indicate RedFlick malware delivery.
• Utilizing sandboxing solutions to analyze the behavior of unknown files or URLs, allowing for the identification of potential RedFlick infections before they reach production environments.
• Enforcing strict password policies and educating users on phishing tactics to reduce the effectiveness of spear-phishing campaigns used by Star Blizzard.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ti•••@cy•••.•••
et•••••.ca
st•••••.org
di•••••.org
mu•••••.net
1f2096••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
9707a8••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dd98db••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
699e92••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
103.245.•••.•••
103.160.•••.•••
2.57.•••.•••
45.84.•••.•••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
January 2026
Threat actors, identified as Russian state actor Star Blizzard, have been using large-scale phishing campaigns and a novel malware delivery technique tracked by Microsoft as "RedFlick" since January 2026.
Click on any entity below to view its context and source!
source_region
Russian Federation
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
tactic
Phishing
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
“Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide,” the company wrote.
organisation
Microsoft
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
threat_actor
Star Blizzard
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog .
industry
Government
“Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide,” the company wrote.
general_metric
13 distinct scale phishing campaigns
“Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide,” the company wrote.
organisation
Microsoft Security Blog
The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog .
Between January and August 2026
Threat actors using the RedFlick technique launched over a dozen phishing and malware campaigns targeting Ukraine between January and August 2026.
Click on any entity below to view its context and source!
target_region
Ukraine
Between January and August 2026, the APT launched over a dozen campaigns containing a RedFlick lure attachment, posing either as Ukrainian authorities or a reputable think tank or NGO.
2026/09/29
Star Blizzard, a Russian government-backed hacking group, has refined its phishing and malware delivery tactics using the RedFlick technique to target governments, think tanks, nonprofits, and financial institutions worldwide.
Click on any entity below to view its context and source!
threat_actor
Star Blizzard
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks.
Russian state-sponsored APT Star Blizzard has updated its tactics, techniques, and procedures (TTPs) in recent attacks to evade detection, Microsoft says.
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond.
Star Blizzard refines phishing and malware delivery with the RedFlick technique.
Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted
spear-phishing campaigns
against academia, defense, governmental organizations, NGOs, and think tanks, and for
using the ClickFix technique
and the
DarkSword iOS exploit kit
.
If the recipient responds to the initial phishing email, Star Blizzard sends a second message containing a password-protected RAR or ZIP archive that triggers the malware delivery.
Star Blizzard, Microsoft says, has been creating accounts on compromised websites to send tens to hundreds of phishing emails per campaign, likely through a mass-mailing phishing platform.
In January, Star Blizzard began sending phishing emails with a malicious Virtual Hard Disk (VHDX) container attached.
“In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns,” Microsoft wrote in a
blog post
.
In April, Star Blizzard started using three RedFlick scheduled tasks for persistence, masquerading as Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.
“Star Blizzard’s shift from ClickFix-based delivery chains to VHDX files, expanded use of scheduled tasks for persistence, and concealment of payloads within PDF files demonstrate the actor’s continued ability to adapt their delivery methods in response to evolving defenses,” Microsoft notes.
The company examined a change in the approach of a group it calls Star Blizzard, which is affiliated with the Russian Federal Security Service (FSB), and its novel malware, RedFlick.
“The actor’s shift from Ukraine-focused operations to global targets could indicate Star Blizzard initially targeted Ukraine to test their new capabilities,” Microsoft wrote.
This isn’t the first time that Microsoft has called out Star Blizzard, with past observations coming in
2023
and
2025
and takedown efforts coming in
2024
.
Star Blizzard has been known by other names as well: SEABORGIUM, Callisto Group, TA446 and
COLDRIVER
.
organisation
APT
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks.
organisation
Microsoft
Russian state-sponsored APT Star Blizzard has updated its tactics, techniques, and procedures (TTPs) in recent attacks to evade detection, Microsoft says.
“In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns,” Microsoft wrote in a
blog post
.
organisation
RedFlick
Star Blizzard refines phishing and malware delivery with the RedFlick technique.
In attacks observed this year, the APT has been relying on large-scale phishing attacks and a new malware delivery technique dubbed
RedFlick
, which requires a single user interaction for malware execution.
The company examined a change in the approach of a group it calls Star Blizzard, which is affiliated with the Russian Federal Security Service (FSB), and its novel malware, RedFlick.
infrastructure
Ios
Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted
spear-phishing campaigns
against academia, defense, governmental organizations, NGOs, and think tanks, and for
using the ClickFix technique
and the
DarkSword iOS exploit kit
.
organisation
the Russian Federal Security Service
Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted
spear-phishing campaigns
against academia, defense, governmental organizations, NGOs, and think tanks, and for
using the ClickFix technique
and the
DarkSword iOS exploit kit
.
The company examined a change in the approach of a group it calls Star Blizzard, which is affiliated with the Russian Federal Security Service (FSB), and its novel malware, RedFlick.
organisation
ClickFix
Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted
spear-phishing campaigns
against academia, defense, governmental organizations, NGOs, and think tanks, and for
using the ClickFix technique
and the
DarkSword iOS exploit kit
.
organisation
DarkSword
Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted
spear-phishing campaigns
against academia, defense, governmental organizations, NGOs, and think tanks, and for
using the ClickFix technique
and the
DarkSword iOS exploit kit
.
organisation
RAR
If the recipient responds to the initial phishing email, Star Blizzard sends a second message containing a password-protected RAR or ZIP archive that triggers the malware delivery.
organisation
VHDX
In January, Star Blizzard began sending phishing emails with a malicious Virtual Hard Disk (VHDX) container attached.
organisation
Callisto Group
Star Blizzard has been known by other names as well: SEABORGIUM, Callisto Group, TA446 and
COLDRIVER
.
victims
100 organizations
It said it has seen the activity affect over 100 organizations that are primarily in the United States or United Kingdom.
infrastructure
Windows
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Related:
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Related:
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related:
Four Cyber Threats Harboring Big Plans for the Future
organisation
ClickFix Attacks
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Related:
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Related:
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related:
Four Cyber Threats Harboring Big Plans for the Future
organisation
PDF
Inside, the group embedded the RedFlick payload: a shortcut file disguised as a PDF document that, when clicked, opens a decoy file while quietly executing a background script.
organisation
MSI
That script fetches an MSI installer, configures scheduled tasks for persistence, and launches the NoroBot or BaitSwitch downloader to deliver the CosmicPulse Python backdoor.
organisation
NoroBot
That script fetches an MSI installer, configures scheduled tasks for persistence, and launches the NoroBot or BaitSwitch downloader to deliver the CosmicPulse Python backdoor.
organisation
BaitSwitch
That script fetches an MSI installer, configures scheduled tasks for persistence, and launches the NoroBot or BaitSwitch downloader to deliver the CosmicPulse Python backdoor.
organisation
LNK
In July, the APT was seen using a multistage execution chain that involved a PowerShell payload executed by the malicious LNK file.
organisation
CosmicPulse
RedFlick has been a key adaptation as “a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor’s custom backdoor, CosmicPulse,” the company said.
organisation
CyberScoop
Written by Tim Starks
Tim Starks is senior reporter at CyberScoop.
organisation
The Washington Post
His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly.
organisation
POLITICO
His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly.
Tactical Metrics
Metrics
infrastructure
Ios
Affected Product
Click for context!
Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted
spear-phishing campaigns
against academia, defense, governmental organizations, NGOs, and think tanks, and for
using the ClickFix technique
and the
DarkSword iOS exploit kit
.
Metrics
infrastructure
Windows
Affected Product
Related:
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Related:
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Related:
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related:
Four Cyber Threats Harboring Big Plans for the Future
Metrics
victims
100
Organizations
It said it has seen the activity affect over 100 organizations that are primarily in the United States or United Kingdom.
Intelligence Sources
CyberScoop
2026-09-29
AlienVault OTX
2026-09-30
SecurityWeek
2026-09-30
AlienVault OTX
2026-09-29
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:40
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
Microsoft
entity
6x
timeline
Temporal Reference
January 2026
date
5x
industry
Targeted Sector
Government
sector
4x
target region
Target Country
Ukraine
country
4x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
3x
tactic
Cyber Operation Type
Phishing
tactic
2x
source region
Origin Country
Russian Federation
country
2x
infrastructure
Affected Product
Ios
software
Contextual Telemetry
Context Block
5 METRICS
threat actor
APT Group
Star Blizzard
actor
general metric
Russian Centre
18
russian centre
attribution
Attributing Entity
Microsoft
authority
victims
Organizations
100
organizations
general metric
Distinct Scale Phishing Campaigns
13
distinct scale phishing campaigns
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.