Russian Threat Actor Star Blizzard Adopted RedFlick Malware

The group transitioned to advanced phishing techniques designed to evade detection and compromise more targets.

Updated on Sept. 30, 2026 in Cybersecurity

Isometric editorial illustration of a heavy rusted padlock with a glowing metallic filament bypassing its shackle, representing advanced malware techniques.
Russian threat actor Star Blizzard has upgraded its phishing operations by adopting RedFlick malware, enabling more efficient backdoor deployment while successfully evading security detection mechanisms. AI Illustration. Upload story photo >

Live Poll

Do you trust that your organization has sufficient security measures to block modern phishing attempts?

The Russian threat actor Star Blizzard has adopted the RedFlick malware delivery technique to enhance its phishing operations. This shift aims to minimize user interaction requirements and increase the success rate of device compromises.

Why it matters

By evolving its delivery methods, Star Blizzard continues to adapt its operations to maintain access to targets despite increased scrutiny. The shift to RedFlick allows the group to deploy backdoors more efficiently while avoiding security detection.

RedFlick employs LNK files disguised as documents to trigger MSI installers, which subsequently execute scheduled tasks. The chain utilizes native Windows utilities like conhost.exe and cmd.exe to launch backdoors such as CosmicPulse with minimal user input.

The players

Star Blizzard

This is a Russian threat actor group known for conducting cyber-espionage operations and phishing campaigns.

Russian Federal Security Service Center 18

This government entity serves as the parent organization overseeing the activities of the Star Blizzard threat actor.

Microsoft

This technology corporation provides security monitoring services and coordinates with law enforcement to disrupt malicious domain infrastructure.

Proofpoint

This cybersecurity firm conducts threat intelligence analysis and identifies novel attack vectors used by nation-state actors.

The details

Star Blizzard transitioned from the ClickFix technique to RedFlick to bypass security controls. The group demonstrated an infection chain in July 2026 that used a PDF-hidden PowerShell payload to deploy malicious software.

Timeline

  1. Star Blizzard began its active operations in 2017.

  2. Microsoft and the DOJ seized 41 domains associated with the group in 2024.

  3. The group adopted RedFlick and altered phishing tactics in January 2026.

  4. Phishing campaigns expanded beyond Ukraine and began targeting iOS devices in March 2026.

  5. The actor utilized a PDF-hidden PowerShell payload for infections in July 2026.

The Tech Race

This development marks a shift in how state-sponsored actors deploy the CosmicPulse backdoor to maintain persistence. The move reflects an ongoing arms race between threat groups seeking to evade endpoint security and developers updating defensive software.

Users should exercise increased caution when interacting with LNK files or unexpected PDF documents, as these are now common vectors for malware. Organizations should ensure that endpoint security software is updated to detect the specific PowerShell payloads used in these campaigns.

The takeaway

Threat actors are increasingly focusing on minimizing the steps required for a user to trigger an infection chain. Staying vigilant against suspicious file attachments remains the most effective defense against modern, automated delivery techniques.

Further reading

Learn more about evolving digital threats in the Cybersecurity section.

Live Poll

Do you trust that your organization has sufficient security measures to block modern phishing attempts?