Star Blizzard refines phishing and malware delivery with the RedFlick technique
Microsoft details Star Blizzard's RedFlick technique delivering CosmicPulse backdoor via single-click phishing lures, hitting 100+ organizations supporting Ukraine.
Microsoft reports Russian state actor Star Blizzard, attributed by CISA as subordinate to FSB Centre 18, shifted since January 2026 from targeted spear phishing to large-scale campaigns using accounts on compromised websites and a new delivery technique tracked as RedFlick. RedFlick initiates scheduled tasks to deploy the custom CosmicPulse backdoor after a single user interaction, replacing earlier multi-step ClickFix chains. Campaigns with lures such as fake Ukrainian tax-audit notices and closed-door policy roundtable invitations have affected over 100 organizations, primarily in the United States and United Kingdom, with a nexus to supporting Ukraine. The blog provides IOCs, detections, and hunting guidance for RedFlick-related activity.