Thehackernews Star Blizzard Expands Phishing Operations with RedFlick Technique
Article Content
- •Star Blizzard has launched over 13 large-scale phishing campaigns since January 2026.
- •The new RedFlick technique allows malware deployment with just one user interaction.
- •Targeted organizations include NGOs, think tanks, and government entities, primarily in the U.S. and U.K.
Russian state-sponsored hacking group Star Blizzard has significantly escalated its phishing operations since January 2026, targeting over 100 organizations, primarily in the U.S. and U.K. The group has shifted from targeted spear-phishing to large-scale campaigns, employing a new malware delivery method called RedFlick. This technique requires only a single user interaction to deploy the CosmicPulse backdoor, making it easier to compromise victims. Star Blizzard has been observed using accounts created on compromised websites to send phishing emails, which typically include password-protected archives that conceal malicious payloads. The campaigns have affected various sectors, including NGOs, think tanks, and government institutions, with at least 13 distinct campaigns reported. The actor's tactics have evolved from earlier methods, such as ClickFix, to enhance their evasion capabilities and broaden their reach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track BlueCharlie, NeedyMantis and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What organizations are targeted?
How does the RedFlick technique work?
What should organizations do to protect themselves?
Continue Reading
Apple Patches CoreGraphics Zero-Day Exploited in Targeted Attacks Apple has released emergency updates for iOS, iPadOS, and macOS to address a critical zero-day vulnerability, CVE-2026-86950, in its CoreGraphics framework. This out-of-bounds write flaw can allow arbitrary code execution when a device processes a maliciously crafted file. The vulnerability was reportedly exploited in…
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…