Home / Oct 01, 2026 / Story
0
#9 SecurityWeek general September 30, 2026 at 10:59 UTC

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

By Ionut Arghire

AI Summary

Russian FSB-linked APT Star Blizzard has adopted a new phishing technique called 'RedFlick' to deploy the CosmicPulse backdoor, replacing its previous ClickFix-style infection chain and expanding targeting to NGOs, think tanks, journalists, and Ukrainian-linked targets in the US and UK. Microsoft observed that the campaign requires only a single victim interaction and relies on sheer volume for success, indicating a shift toward higher-throughput, lower-sophistication lure design. Security teams supporting civil society and government-adjacent organizations should update phishing awareness training accordingly.

Relevance score: 76.0/100

# More from October 01