Skip to content
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Securityweek •Ionut Arghire • September 30, 2026

Russian state- APT Star Blizzard has updated its tactics, techniques, and procedures (TTPs) in recent attacks to evade detection, Microsoft says.

Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted spear-phishing campaigns against academia, defense, governmental organizations, NGOs, and think tanks, and for using the ClickFix technique and the DarkSword iOS exploit kit .

In attacks observed this year, the APT has been relying on large-scale phishing attacks and a new malware delivery technique dubbed RedFlick , which requires a single user interaction for malware execution.

If the recipient responds to the initial phishing email, Star Blizzard sends a second message containing a password-protected RAR or ZIP archive that triggers the malware delivery.

The state- group has been using the technique in attacks against Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have been providing support to Ukraine.

Star Blizzard, Microsoft says, has been creating accounts on compromised websites to send tens to hundreds of phishing emails per campaign, likely through a mass-mailing phishing platform.

Between January and August 2026, the APT launched over a dozen campaigns containing a RedFlick lure attachment, posing either as Ukrainian authorities or a reputable think tank or NGO. The emails were crafted to appear to come from within the targeted organization.

In January, Star Blizzard began sending phishing emails with a malicious Virtual Hard Disk (VHDX) container attached. Inside, the group embedded the RedFlick payload: a shortcut file disguised as a PDF document that, when clicked, opens a decoy file while quietly executing a background script.

That script fetches an MSI installer, configures scheduled tasks for persistence, and launches the NoroBot or BaitSwitch downloader to deliver the CosmicPulse Python backdoor.

In April, Star Blizzard started using three RedFlick scheduled tasks for persistence, masquerading as Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.

In July, the APT was seen using a multistage execution chain that involved a PowerShell payload executed by the malicious LNK file. The PowerShell attempted to fetch another MSI file that attempted to create two additional scheduled tasks.

“Star Blizzard’s shift from ClickFix-based delivery chains to VHDX files, expanded use of scheduled tasks for persistence, and concealment of payloads within PDF files demonstrate the actor’s continued ability to adapt their delivery methods in response to evolving defenses,” Microsoft notes.

Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Related: Four Cyber Threats Harboring Big Plans for the Future

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Reco Raises $55 Million for Agentic Security

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

DC Health Agency Exposes 400,000 Beneficiary Records

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

ShinyHunters Defiant After FBI Calls on Members to Come Forward

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

DARPA Selects Xint to Use AI in Securing Military Messaging Apps

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

RemoteThreat Launches With $7 Million for Offensive Operations Platform

Flipboard Whatsapp Whatsapp Email

Extracted Entities

APT Groups (1)

Attack Types (2)

Countries (1)

Domains (1)

Industries (1)

Platforms (1)

Tools (1)