INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Star Blizzard Utilizes RedFlick Technique for Phishing and Malware Delivery

| 2026-09-29 15:56 CRITICAL HIGH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Microsoft has identified a significant shift in the tactics, techniques, and procedures (TTPs) of Russian state-sponsored Advanced Persistent Threat (APT) group Star Blizzard. Since January 2026, Star Blizzard has evolved its detection evasion capabilities through large-scale phishing campaigns, compromised website accounts, and a novel malware delivery technique dubbed "RedFlick." These changes represent a notable shift in the actor's operational tradecraft and support ongoing cyberespionage activity targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy. The RedFlick technique has been used to refine phishing and malware delivery, allowing Star Blizzard to evade detection more effectively. This update highlights the evolving threat landscape and underscores the importance of continued vigilance in detecting and mitigating cyber threats from state-sponsored actors.
Technical Mitigations AI-generated
• Implementing behavioral analysis and machine learning-based detection to identify anomalies in user interactions that may indicate RedFlick malware delivery. • Utilizing sandboxing solutions to analyze the behavior of unknown files or URLs, allowing for the identification of potential RedFlick infections before they reach production environments. • Enforcing strict password policies and educating users on phishing tactics to reduce the effectiveness of spear-phishing campaigns used by Star Blizzard.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ti•••@cy•••.•••
et•••••.ca
st•••••.org
di•••••.org
mu•••••.net
1f2096••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
9707a8••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
dd98db••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
699e92••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
103.245.•••.•••
103.160.•••.•••
2.57.•••.•••
45.84.•••.•••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎January 2026
Threat actors, identified as Russian state actor Star Blizzard, have been using large-scale phishing campaigns and a novel malware delivery technique tracked by Microsoft as "RedFlick" since January 2026.
source_region Russian Federation
tactic Phishing
organisation Microsoft
threat_actor Star Blizzard
industry Government
general_metric 13 distinct scale phishing campaigns
organisation Microsoft Security Blog
‎Between January and August 2026
Threat actors using the RedFlick technique launched over a dozen phishing and malware campaigns targeting Ukraine between January and August 2026.
target_region Ukraine
‎2026/09/29
Star Blizzard, a Russian government-backed hacking group, has refined its phishing and malware delivery tactics using the RedFlick technique to target governments, think tanks, nonprofits, and financial institutions worldwide.
threat_actor Star Blizzard
organisation APT
organisation Microsoft
organisation RedFlick
infrastructure Ios
organisation the Russian Federal Security Service
organisation ClickFix
organisation DarkSword
organisation RAR
organisation VHDX
organisation Callisto Group
victims 100 organizations
infrastructure Windows
organisation ClickFix Attacks
organisation PDF
organisation MSI
organisation NoroBot
organisation BaitSwitch
organisation LNK
organisation CosmicPulse
organisation CyberScoop
organisation The Washington Post
organisation POLITICO
Tactical Metrics
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
100
Organizations