Skip to content
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Darkreading •Elizabeth Montalbano • September 30, 2026

The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.

A Russia-linked advanced persistent threat (APT) actor that was significantly disrupted by Microsoft and US officials two years ago is casting a wider net than ever with its phishing and malware-delivery tactics. In recent attacks, the nation-state actor has ditched its ClickFix strategy for a novel technique, allowing it to reach even more targets and evade detection.

Star Blizzard, active since 2017 and known for targeting journalists, nongovernmental organizations (NGOs), and Russia experts — particularly those supporting Ukraine — has since January demonstrated a key tactical change in its phishing initial-access method, Microsoft Threat Intelligence (MTI) revealed in a blog post on Sept. 29.

"As part of this evolution, Star Blizzard adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor , CosmicPulse," according to MTI's post.

Related: 'NeedyMantis' Provides Long-Term Access to Compromised Networks

The technique signals a departure from the actor's use of the social engineering tactic ClickFix , which required several actions by the victim before deploying CosmicPulse, a Python-based backdoor, Microsoft said. "By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process," according to the post.

This change, combined with the actor's shift toward large-scale phishing operations during the same period, likely increases the APT's chance of success, Microsoft warned, which should put organizations typically in Star Blizzard's crosshairs on alert.

Latest Star Blizzard Activity

Star Blizzard, also referred to as ColdRiver and Callisto, is a subordinate to the Russian Federal Security Service Center (FSB) Center 18, according to the US Cybersecurity and Infrastructure Security Agency (CISA). In the past, the actor primarily used phishing emails to steal login credentials from its victims and was the target of a 2024 joint operation by Microsoft and the Department of Justice to seize 41 of Star Blizzard's Internet domains.

Undaunted, Star Blizzard has continued to evolve, with Microsoft detecting 13 distinct "large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide" since January. Though early campaigns targeted users of the Ukrainian email provider Ukr.net by impersonating Ukrainian tax or other authorities, campaigns starting in March expanded beyond Ukraine.

Indeed, Star Blizzard has significantly widened the scale of its email attacks, sending hundreds of messages per campaign in contrast to its , carefully researched and narrowly focused spear-phishing operations. The lures remain similar to campaigns, impersonating tax authorities, financial organizations, and prominent think tanks, or sending fake invitations to closed-door security, diplomatic, economic, and geopolitical events, Microsoft said.

Related: UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

"Microsoft also observed the actor target multiple individuals within the same organization, with phishing emails often crafted to appear as internal communications originating from the targeted organization itself," according to the post.

Furthermore, in new campaigns, Star Blizzard is showing off new capabilities previously unassociated with the actor, including steganography to conceal identifiers and the targeting of vulnerable Apple iOS devices to deploy the DarkSword backdoor , as reported by Proofpoint in March.

Various RedFlick Infection Paths

RedFlick signals a major change to how Star Blizzard is targeting victims through email, Microsoft said. RedFlick is a malware delivery and persistence technique with various infection paths that all a common thread: an effort to make malicious execution blend into normal Windows activity while reducing the amount of work required from the victim.

Related: Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

In campaigns observed by Microsoft, victims receive password-protected zip or RAR archives containing an LNK file disguised as a document, often a PDF. The LNK uses Windows utilities such as conhost.exe and cmd.exe to start the infection chain via an MSI installer that creates scheduled tasks to execute malware, reducing the manual steps required compared with the actor's earlier ClickFix campaigns.

Star Blizzard in July demonstrated another infection chain that required little more than the victim opening a lure and used trusted Windows components to handle execution, persistence, and payload retrieval, according to Microsoft. This chain hid PowerShell payload data inside an apparently legitimate PDF , which eventually created scheduled tasks and ultimately launched the CPL-based CosmicPulse downloader with minimal user interaction.

Piyush Sharma, co-founder and CEO of security firm Tuskira, says the speed with which Star Blizzard is reducing its interaction with victims on its way to compromising them is notable, demonstrating rapid evolution and determination in the actor's latest phishing attacks .

"What interests me RedFlick is how much work it takes away from the victim," he says, adding that he is particularly impressed by the PowerShell technique that surfaced in July to hide part of the delivery chain inside a PDF.

"That’s a lot of adjustment in a few months, with the same backdoor still at the end of it," Sharma observes.

Defending Against Changing Star Blizzard Tactics

Though Star Blizzard has changed its tactics, its overall phishing patterns remain the same, and Microsoft advised organizations to set their security defenses accordingly. Recommended mitigations include using phishing-resistant authentication methods; locking down account access using conditional access policies; and using advanced anti-phishing solutions that monitor and scan incoming emails and visited websites.

Organizations also should continue with other general security mitigations to reduce the impact of a successful initial entry via Star Blizzard's attack chain, including using endpoint detection and response (EDR) in block mode to block malicious artifacts.

Microsoft also encouraged organizations to use Web browsers that support Microsoft Defender SmartScreen, which identifies and blocks malicious websites, including phishing sites, scam sites, and sites that host malware.

Tuskira's Sharma warns that other threat groups may attempt to copy Star Blizzards' RedFlick techniques going forward. Thus, he advises defenders to test whether their security controls "catch the chain after the click, from the scheduled tasks through to the backdoor," and then repeat those tests as the packaging of the infection chain changes.

Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician.

Want more Dark Reading stories in your Google results?

The State of Cloud Security: The Latest Challenges

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Essential News & Insights from Black Hat USA 2025

Effective Alert Triage: Reducing Noise and Finding Real Threats

Effective Alert Triage: Reducing Noise and Finding Real Threats

Cybersecurity Outlook 2027

Cybersecurity Outlook 2027

Threat Exposure Analytics: Measuring and Communicating Security Risk

Threat Exposure Analytics: Measuring and Communicating Security Risk

Benchmark Scores Are a False Flag

Benchmark Scores Are a False Flag

Building an Effective Red Team: Beyond Penetration Testing

Building an Effective Red Team: Beyond Penetration Testing

Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish

Iran's Cyber-Kinetic War Doctrine Takes Shape

React2Shell Exploits Flood the Internet as Attacks Continue

Chinese Gov't Fronts Trick the West to Obtain Cyber Tech