Star Blizzard Evolves with RedFlick Technique for Enhanced Phishing and Malware Delivery
Russian state-sponsored threat actor Star Blizzard is employing a new malware delivery technique called RedFlick, significantly enhancing its phishing campaigns and ability to deploy the CosmicPulse backdoor.

Russian state-sponsored threat actor Star Blizzard has demonstrated a notable evolution in its operational tradecraft throughout 2026, refining its detection evasion capabilities through large-scale phishing campaigns and the adoption of a novel malware delivery technique dubbed "RedFlick." This evolution supports ongoing cyberespionage activities primarily targeting Ukrainian entities, international non-governmental organizations (NGOs), Western think tanks, and governments, particularly those with a focus on supporting Ukraine. Microsoft has observed this activity affect over 100 organizations, with a significant number in the United States and United Kingdom.
The RedFlick technique represents a significant departure from Star Blizzard's previous methods, which often required multiple user interactions to deploy the CosmicPulse backdoor. RedFlick streamlines this process by initiating a set of scheduled tasks, reducing the necessary user interaction to a single click. This simplification, combined with the actor's shift towards mass-mailing phishing operations, is designed to increase the speed and scale of compromises, allowing Star Blizzard to reach more targets and improve the likelihood of successful intrusions.
Star Blizzard, attributed by CISA as subordinate to the Russian Federal Security Service (FSB) Centre 18, periodically overhauls its tactics, techniques, and procedures (TTPs) to evade detection, often in response to public exposure of its campaigns. Following reports on the actor's COLDCOPY malware in late 2025, Microsoft observed Star Blizzard pivot towards using compromised websites for account creation to send phishing emails and updating its malware deployment mechanisms.
While Star Blizzard previously relied on targeted spear-phishing, 2026 saw a substantial increase in larger-scale phishing campaigns, ranging from tens to hundreds of emails per operation. These campaigns have employed subject lines in both Russian and English, often impersonating official communications such as tax audit results or account debits, and invitations to high-level discussions on European security. These lures are designed to entice recipients into opening attachments or clicking malicious links that initiate the RedFlick infection chain.
The RedFlick infection flow, once triggered, leverages scheduled tasks to deploy a downloader for the CosmicPulse backdoor. This method is more efficient than prior ClickFix-based infection chains, which were more complex and required greater user engagement. The reduced friction in the compromise process is a key factor in the actor's increased operational effectiveness.
Microsoft Defender has detections for RedFlick-related activity, and the company provides specific hunting queries and indicators of compromise (IOCs) to help organizations identify and defend against these evolving threats. The ongoing targeting of entities involved in supporting Ukraine underscores the geopolitical motivations behind Star Blizzard's cyberespionage operations.
This latest evolution in Star Blizzard's TTPs highlights the persistent and adaptive nature of state-sponsored threat actors. The adoption of RedFlick and the shift to large-scale phishing demonstrate a strategic effort to enhance operational efficiency and broaden their reach, posing a continued threat to organizations involved in international policy and security.
The latest reporting from Microsoft details Star Blizzard's continued evolution, highlighting their shift to a new malware delivery technique dubbed RedFlick. This method leverages scheduled tasks to install the CosmicPulse backdoor, a departure from previous tactics like the ClickFix CAPTCHA pages. Furthermore, the group has begun exploiting compromised WordPress and cPanel websites for their command-and-control infrastructure, moving away from free email services.