www.securityweek.com 30 Sept 2026, 10:59 UTC

Star Blizzard’s RedFlick Phishing Chain Needs One Click to Deploy Malware

Star Blizzard’s RedFlick Phishing Chain Needs One Click to Deploy Malware
CyberSIXT Evidence Panel
Threat Actor
🇷🇺 Callisto

MICROSOFT reports that Russian state‑backed APT Star Blizzard has refreshed its TTPs to evade detection, expanding large‑scale phishing campaigns and a new RedFlick infection chain that requires only a single user action for malware execution. In attacks observed between January and August 2026, the group used mass‑mail phishing, creating accounts on compromised websites to dispatch tens to hundreds of messages per campaign. The lure emails typically imitate Ukrainian authorities, think tanks or NGOs, and appear to originate from within the target organisation.

The RedFlick technique involves an initial phishing email delivering a VHDX container, with a shortcut disguised as a PDF that, when opened, runs a background script. That script retrieves an MSI installer, sets up persistence via scheduled tasks, and launches a downloader such as NoroBot or BaitSwitch to deliver the CosmicPulse backdoor.

Microsoft notes multiple evolutions: three RedFlick scheduled tasks for persistence in April, a multistage execution chain in July using PowerShell via a malicious LNK file, and attempts to create additional scheduled tasks.

The campaigns targeted Ukrainian individuals and institutions, along with international NGOs, think tanks, governments and financial entities supporting Ukraine, highlighting Star Blizzard’s continued adaptation to bypass newer defences while shifting away from ClickFix chains toward VHDX and PDF‑embedded payloads.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline