Russia’s Star Blizzard Ditches ClickFix to Widen Phishing Net

Russia’s Star Blizzard APT Actor Widenits its Phishing Net with RedFlick Tactic

The Russia-linked advanced persistent threat (APT) actor known as Star Blizzard has significantly expanded its phishing operations, using a new tactic called RedFlick to evade detection and reach even more targets. In recent attacks, the group has ditched its previous ClickFix strategy, opting for a novel technique that allows it to deploy its CosmicPulse backdoor with minimal user interaction.

Star Blizzard, active since 2017, has been targeting journalists, non-governmental organizations (NGOs), and Russia experts – particularly those supporting Ukraine. However, the group’s tactics have evolved over time, and in January, Microsoft detected a significant shift towards large-scale phishing operations. This change is likely to increase Star Blizzard’s chances of success, as it can now reach a wider audience with minimal effort.

The new RedFlick technique involves initiating a set of scheduled tasks to deploy the CosmicPulse backdoor, which helps evade detection by blending malicious activity into normal Windows behavior. Unlike the previous ClickFix tactic, which required several actions from the victim before deploying the backdoor, RedFlick only requires a single user interaction – making it easier for the actor to compromise its targets.

The shift towards large-scale phishing operations is also notable, with Microsoft detecting 13 distinct campaigns targeting NGOs, think tanks, and government organizations worldwide since January. These campaigns often impersonate tax authorities, financial organizations, or prominent think tanks, and have expanded beyond Ukraine’s borders. Star Blizzard has also been observed targeting multiple individuals within the same organization, using phishing emails that appear to be internal communications.

Furthermore, the actor has demonstrated new capabilities in recent campaigns, including steganography to conceal identifiers and the targeting of vulnerable Apple iOS devices with the DarkSword backdoor. This expansion of tactics suggests that Star Blizzard is becoming increasingly sophisticated and adaptable – making it a formidable threat to organizations typically in its crosshairs.

The practical takeaway for readers is clear: with the shift towards large-scale phishing operations, organizations should be on high alert for potential attacks from Star Blizzard. By staying informed about the latest tactics and techniques used by this APT actor, organizations can better prepare themselves against these types of threats.


Source: Dark Reading — 2026-09-30