Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Microsoft says Russian APT Star Blizzard now delivers backdoors through its RedFlick phishing chain.
Microsoft says Russian state-sponsored Star Blizzard, linked to FSB Centre 18, is using a new RedFlick delivery chain in observed 2026 attacks. After a phishing reply, victims receive a password-protected archive or VHDX containing a shortcut disguised as a PDF; one click opens a decoy while a script fetches an MSI, creates scheduled tasks, and launches NoroBot or BaitSwitch to deliver the CosmicPulse Python backdoor. From January through August the group ran more than a dozen campaigns against Ukrainian targets and supporting NGOs, think tanks, governments, and financial institutions. Later activity added extra scheduled tasks and a PowerShell stage.