Star Blizzard Refines Phishing with RedFlick Technique
Microsoft has reported that Russian state threat actor Star Blizzard has refined its phishing and malware delivery techniques, dubbed 'RedFlick', to evade detection. Since January 2026, Star Blizzard has shifted from targeted spear-phishing operations to larger-scale initial contact phishing campaigns, targeting over 100 organizations in the United States and United Kingdom.
The RedFlick technique involves initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse. This approach reduces friction in the compromise process by requiring only a single user interaction.
Microsoft notes that Star Blizzard has adopted a mass-mailing phishing platform to automate campaign execution and increase the likelihood of successful compromises. The actor's tactics, techniques, and procedures (TTPs) have evolved over time, with the adoption of RedFlick representing a notable departure from previous methods.