Sam's News โ email-security โ 2026-10-03¶
Email Security¶
7 Star Blizzard adopts RedFlick malware delivery technique to refine phishing attacks¶
Microsoft revealed that Russian state-sponsored threat actor Star Blizzard has evolved its tactics since January 2026, adopting a new malware delivery method called RedFlick that requires only a single user interaction to deploy the CosmicPulse backdoor. The technique marks a significant shift from the actor's previous ClickFix-based approach and is being used in large-scale phishing campaigns targeting Ukrainian institutions, NGOs, Western think tanks, and governments.
- RedFlick requires only single user interaction versus multiple actions needed for previous ClickFix chains
- Star Blizzard targets Ukrainian individuals, institutions, NGOs, think tanks, and governments supporting Ukraine
- RedFlick uses scheduled tasks to evade detection and deploy CosmicPulse backdoor
- Evolution observed since January 2026 as part of ongoing cyberespionage operations
Sources: Microsoft Security Blog AI Web Searched