#RedFlick
Since January 2026, Microsoft has observed Russian state actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique tracked as RedFlick. msft.it/63328act10
Star Blizzard refines phishing and malware delivery with the RedFlick technique | Microsoft Security Blog
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
msft.it
September 29, 2026 at 3:03 PM
Star Blizzard's RedFlick needs one click to plant a Python backdoor via disguised scheduled tasks. https://intel.threadlinqs.com/threat/TL-2026-2787 #ThreatIntel #YESROBOT #NOROBOT #MAYBEROBOT
September 29, 2026 at 11:27 PM
Star Blizzard went mass-phish and now abuses ssh.exe to drop a Python backdoor. https://intel.threadlinqs.com/threat/TL-2026-2795 #ThreatIntel #CosmicPulse #RedFlick #NOROBOT
September 30, 2026 at 12:51 AM
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

www.securityweek.com/russian-apt-...

#Kyberturvallisuus #Kyber #Tilannekuva
Russian APT Star Blizzard Uses 'RedFlick' Infection Chain in Recent Attacks
Russian state-sponsored group Star Blizzard has been using the RedFlick infection technique in recent CosmicPulse attacks.
www.securityweek.com
September 30, 2026 at 11:18 AM
@microsoft.com
Star Blizzard uses RedFlick scheduled tasks to deliver CosmicPulse in scalable phishing campaigns.
-
IOCs: secure-dns-hub[.]com, etia[.]ca, gliderrompercycl[.]com
-
#Malware #Phishing #ThreatIntel
Star Blizzard RedFlick Phishing
www.microsoft.com
September 29, 2026 at 8:12 PM
Star Blizzard refina entrega de malware con técnica RedFlick

El grupo Star Blizzard mejora sus campañas de phishing y entrega de malware con la…

https://mentehackers.com/star-blizzard-refina-entrega-de-malware-con-tecnica-redflick-a7f2937e
#Ciberseguridad #Tecnologia #MenteHackers
Star Blizzard refina entrega de malware con técnica RedFlick
El grupo Star Blizzard mejora sus campañas de phishing y entrega de malware con la técnica RedFlick. Usa ahora un solo paso para infectar sistemas.
mentehackers.com
September 29, 2026 at 4:40 PM
Star Blizzard refines phishing and malware delivery with the RedFlick technique
https://go.rodtrent.com/go/dtcupx7
September 30, 2026 at 10:05 AM
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft warns Russian threat group Star Blizzard is using new RedFlick phishing campaigns and CosmicPulse malware to target over 100 global organizations.
cyberscoop.com
September 29, 2026 at 8:38 PM
RedFlick can enable CosmicPulse malware installation after a single user interaction, reducing friction in the compromise process. Combined with the actor’s updated TTPs, these changes improve Star Blizzard’s ability to reach more targets and increase the likelihood of successful compromise.
September 29, 2026 at 3:05 PM
Russian FSB-linked Star Blizzard has shifted from spear-phishing to larger phishing campaigns, using RedFlick and CosmicPulse to hit 100+ groups tied to Ukraine and its supporters. #StarBlizzard #Ukraine #FSB
Russian Hackers Star Blizzard Expand Targeting, Change Up Tactics To Reach Ukraine And Beyond
Microsoft says Russian FSB-linked Star Blizzard has expanded from targeted spear-phishing to larger-scale phishing campaigns using the RedFlick delivery method and CosmicPulse backdoor. The activity has hit more than 100 organizations, with a focus on Ukraine, NGOs, think tanks, governments, and supporters of Ukraine in the U.S. and U.K. #StarBlizzard #FSB #RedFlick #CosmicPulse #Ukraine
www.hendryadrian.com
September 30, 2026 at 4:30 AM
Star Blizzard updated phishing and malware delivery methods, using RedFlick with single-click execution and multi-stage password-archive lures to evade detection.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 11:13 AM
Star Blizzard updated phishing and malware delivery methods, using RedFlick with single-click execution and multi-stage password-archive lures to evade detection.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 11:16 AM
Morty. Star Blizzard is RSVPing you into malware again. Fake think-tank invites, passworded ZIP, then a PDF that is secretly an LNK. RedFlick schedules CosmicPulse while Windows does chores. Peak diplomacy: the calendar invite is the payload. day273.005
September 29, 2026 at 8:44 PM
A recent Microsoft blog post provides an updated technical analysis of the Russian threat actor Star Blizzard’s TTPs. In 2026 Star Blizzard adopted RedFlick, a malware delivery technique that helps evade detection and deploy the custom backdoor CosmicPulse. www.microsoft.com/en-us/securi...
September 30, 2026 at 12:37 PM
Targets include NGOs, think tanks, governments, and financial institutions tied to Ukraine support, with over 100 organizations affected

The group now uses compromised websites to send phishing emails and deploys its CosmicPulse backdoor through disguised scheduled tasks requiring only one click
Star Blizzard refines phishing and malware delivery with the RedFlick technique | Microsoft Security Blog
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromis...
www.microsoft.com
September 29, 2026 at 8:54 PM
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond

cyberscoop.com/microsoft-st...

#MilitarySkills #Preparedness #Strategy
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft warns Russian threat group Star Blizzard is using new RedFlick phishing campaigns and CosmicPulse malware to target over 100 global organizations.
cyberscoop.com
September 29, 2026 at 8:56 PM
#cybersécurité #hackingnews
Les hackers russes reviennent aux basiques du piratage et Microsoft rebaptise leur méthode
Les hackers russes reviennent aux basiques du piratage et Microsoft rebaptise leur méthode
Après avoir misé sur ClickFix, le groupe russe Star Blizzard serait revenu à une méthode bien plus classique. Rebaptisé RedFlick par Microsoft, le procédé repose sur ni plus ni moins sur une pièce joi...
www.numerama.com
September 30, 2026 at 10:28 AM
Les hackers russes reviennent aux basiques du piratage et Microsoft rebaptise leur méthode
Les hackers russes reviennent aux basiques du piratage et Microsoft rebaptise leur méthode
Après avoir misé sur ClickFix, le groupe russe Star Blizzard serait revenu à une méthode bien plus classique. Rebaptisé RedFlick par Microsoft, le procédé repose sur ni plus ni moins sur une pièce jointe piégée.
www.numerama.com
September 30, 2026 at 9:14 AM
ロシアのStar Blizzardが、偽のイベント招待でWindowsにバックドアを仕掛ける。ウクライナ関連の100超の組織が標的。
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Star Blizzard uses fake event invites and RedFlick scheduled tasks to install CosmicPulse on Windows systems tied to Ukraine.
thehackernews.com
September 29, 2026 at 7:57 PM
ロシアのAPT「Star Blizzard」、最近の攻撃で感染チェーン「RedFlick」を使用

ロシア政府が支援するAPTグループ「Star Blizzard」が、検知を回避するために、最近の攻撃で戦術・技術・手順(TTP)を更新したことが、Microsoftの調査で明らかになりました。 Star Blizzardは、ロシア連邦保安庁(FSB)第18センターの下部組織とみられています。学術機関、防衛、政府機関、
ロシアのAPT「Star Blizzard」、最近の攻撃で感染チェーン「RedFlick」を使用
ロシア政府が支援するAPTグループ「Star Blizzard」が、検知を回避するために、最近の攻撃で戦術・技術・手順(TTP)を更新したことが、Microsoftの調査で明らかになりました。 Star Blizzardは、ロシア連邦保安庁(FSB)第18センターの下部組織とみられています。学術機関、防衛、政府機関、
blackhatnews.tokyo
September 30, 2026 at 11:09 AM