Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Threat Intel

Russia's Star Blizzard swaps ClickFix for RedFlick

Microsoft says Star Blizzard now uses a one-click technique called RedFlick to deploy its CosmicPulse backdoor against Ukraine-linked targets.

By · Published · Updated · 4 min read

Russia's Star Blizzard swaps ClickFix for RedFlick

Russia-linked hacking group Star Blizzard has changed how it infects victims, Dark Reading reports, citing Microsoft Threat Intelligence.

Who they target

Star Blizzard has been active since 2017 and targets journalists, NGOs, think tanks and Russia experts — especially those supporting Ukraine. Microsoft and US officials disrupted the group two years ago.

What has changed

  • Since January, the group has used a new technique Microsoft calls RedFlick.
  • RedFlick sets up scheduled tasks to install the group's Python backdoor, CosmicPulse.
  • Unlike its previous ClickFix method, which needed several actions from the victim, RedFlick needs just one click.
  • The group has also moved to larger-scale phishing.

Why it matters

Fewer steps means more victims fall for it, and a wider net means people who never considered themselves targets may now receive these emails.

How at-risk groups can protect themselves

  • Verify unexpected documents or meeting requests by contacting the sender another way.
  • Use phishing-resistant sign-in (passkeys or security keys).
  • Consider free protection programmes for high-risk users, such as Google's Advanced Protection.

Sources

Read next