Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
By Ionut Arghire
AI Summary
Russian FSB-linked APT Star Blizzard has adopted a new phishing technique called 'RedFlick' to deploy the CosmicPulse backdoor, replacing its previous ClickFix-style infection chain and expanding targeting to NGOs, think tanks, journalists, and Ukrainian-linked targets in the US and UK. Microsoft observed that the campaign requires only a single victim interaction and relies on sheer volume for success, indicating a shift toward higher-throughput, lower-sophistication lure design. Security teams supporting civil society and government-adjacent organizations should update phishing awareness training accordingly.
Relevance score: 76.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →