Russia-linked threat actor Star Blizzard has significantly expanded its phishing and malware-delivery tactics, making it harder for victims to detect and evade. The group, known for targeting journalists, NGOs, and experts on Ukraine, has abandoned its previous ClickFix strategy in favor of a new technique called RedFlick. This shift allows Star Blizzard to reach even more targets with ease.
RedFlick is a malware delivery method that initiates a series of scheduled tasks to deploy the actor’s custom backdoor, CosmicPulse. Unlike its previous tactic, ClickFix, which required multiple user interactions before deploying the backdoor, RedFlick only needs one interaction from the victim. This reduced friction increases Star Blizzard’s chances of success in compromising networks.
Star Blizzard has been active since 2017 and has a history of targeting organizations and individuals linked to Ukraine. The group is subordinate to Russia’s Federal Security Service Center (FSB) Center 18, according to the US Cybersecurity and Infrastructure Security Agency (CISA). In the past, Star Blizzard primarily used phishing emails to steal login credentials from its victims and was disrupted in a joint operation by Microsoft and the Department of Justice in 2024.
However, undeterred by this setback, Star Blizzard has continued to evolve. Since January, Microsoft has detected 13 large-scale phishing campaigns targeting NGOs, think tanks, and government organizations worldwide. These campaigns often impersonate tax authorities or other legitimate organizations, making it harder for victims to distinguish between genuine and malicious communications.
One of the key changes in Star Blizzard’s tactics is its shift towards broad-scale phishing operations. In contrast to its previous, carefully researched spear-phishing operations, the group now sends hundreds of messages per campaign, targeting multiple individuals within the same organization. These emails often appear as internal communications, making it harder for victims to detect them.
Furthermore, Microsoft has observed Star Blizzard deploying new capabilities, including steganography to conceal identifiers and targeting vulnerable Apple iOS devices with the DarkSword backdoor. This expansion of tactics highlights the need for organizations to remain vigilant in protecting themselves against this evolving threat actor.
What does this mean for your organization? It’s essential to be aware of these changes in Star Blizzard’s tactics and take proactive measures to protect yourself. Implement robust email security controls, such as advanced phishing detection and anti-spam filters, to reduce the risk of falling victim to these attacks. Additionally, educate your staff on how to identify and report suspicious emails, and ensure that all software and systems are up-to-date with the latest security patches.
In conclusion, Star Blizzard’s shift towards RedFlick and large-scale phishing operations highlights the importance of staying informed about evolving threat actors and tactics. By understanding these changes and taking proactive steps to protect yourself, you can reduce your organization’s risk of being compromised by this sophisticated threat actor.
Source: Dark Reading — 2026-09-30