Skip to content
Star Blizzard Expands Phishing Operations with RedFlick Technique

Star Blizzard Expands Phishing Operations with RedFlick Technique

First seen 29 Sep 2026, 19:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 18:35 UTC
  • •Star Blizzard has launched over 13 large-scale phishing campaigns since January 2026.
  • •The new RedFlick technique allows malware deployment with just one user interaction.
  • •Targeted organizations include NGOs, think tanks, and government entities, primarily in the U.S. and U.K.

Russian state-sponsored hacking group Star Blizzard has significantly escalated its phishing operations since January 2026, targeting over 100 organizations, primarily in the U.S. and U.K. The group has shifted from targeted spear-phishing to large-scale campaigns, employing a new malware delivery method called RedFlick. This technique requires only a single user interaction to deploy the CosmicPulse backdoor, making it easier to compromise victims. Star Blizzard has been observed using accounts created on compromised websites to send phishing emails, which typically include password-protected archives that conceal malicious payloads. The campaigns have affected various sectors, including NGOs, think tanks, and government institutions, with at least 13 distinct campaigns reported. The actor's tactics have evolved from earlier methods, such as ClickFix, to enhance their evasion capabilities and broaden their reach.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-01-01
Star Blizzard begins large-scale phishing campaigns
The group shifts from targeted spear-phishing to broader phishing operations, affecting over 100 organizations.
Microsoft
2026-03-01
RedFlick technique adopted
Star Blizzard starts using the RedFlick malware delivery method, requiring only one user interaction for deployment.
Darkreading
2026-09-29
Microsoft publishes updated threat report
Microsoft details the evolution of Star Blizzard's tactics and the impact of RedFlick on their phishing operations.
Microsoft

More articles in this cluster (15)

Following this threat?

Track BlueCharlie, NeedyMantis and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What organizations are targeted?
Star Blizzard targets NGOs, think tanks, and government institutions, primarily in the U.S. and U.K.
How does the RedFlick technique work?
RedFlick requires only one user interaction to deploy the CosmicPulse backdoor, making it easier for attackers to compromise systems.
What should organizations do to protect themselves?
Organizations should implement robust email security measures, educate users on phishing tactics, and monitor for suspicious activity.