Russia's Star Blizzard swaps ClickFix for RedFlick
Microsoft says Star Blizzard now uses a one-click technique called RedFlick to deploy its CosmicPulse backdoor against Ukraine-linked targets.
By Priya Nair · Published · Updated · 4 min read

Russia-linked hacking group Star Blizzard has changed how it infects victims, Dark Reading reports, citing Microsoft Threat Intelligence.
Who they target
Star Blizzard has been active since 2017 and targets journalists, NGOs, think tanks and Russia experts — especially those supporting Ukraine. Microsoft and US officials disrupted the group two years ago.
What has changed
- Since January, the group has used a new technique Microsoft calls RedFlick.
- RedFlick sets up scheduled tasks to install the group's Python backdoor, CosmicPulse.
- Unlike its previous ClickFix method, which needed several actions from the victim, RedFlick needs just one click.
- The group has also moved to larger-scale phishing.
Why it matters
Fewer steps means more victims fall for it, and a wider net means people who never considered themselves targets may now receive these emails.
How at-risk groups can protect themselves
- Verify unexpected documents or meeting requests by contacting the sender another way.
- Use phishing-resistant sign-in (passkeys or security keys).
- Consider free protection programmes for high-risk users, such as Google's Advanced Protection.


