{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/star-blizzard/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Star Blizzard"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["phishing","espionage","redflick","cosmicpulse","star-blizzard","windows","macos"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eSince January 2026, the Russian state-sponsored threat actor Star Blizzard (subordinate to FSB Centre 18) has evolved its operational tradecraft to include large-scale phishing campaigns and a novel malware delivery mechanism dubbed \u0026quot;RedFlick.\u0026quot; This pivot represents a significant departure from previous, more targeted spear-phishing operations, allowing the actor to scale operations significantly by utilizing automated mass-mailing platforms. The RedFlick technique streamlines the infection chain, requiring only a single user interaction to initiate the deployment of the custom CosmicPulse backdoor. These operations target individuals and institutions supporting Ukraine, including government officials, NGOs, think tanks, and international financial organizations, particularly within the United States and the United Kingdom. With over 100 organizations affected, this evolution indicates a persistent and adaptive threat capable of rapid TTP iteration in response to public disclosure and defensive hardening.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe actor conducts reconnaissance to identify targets associated with Ukraine, financial policy, or international relations.\u003c/li\u003e\n\u003cli\u003eMass-phishing emails are distributed using accounts on compromised websites to bypass reputation filters, impersonating legitimate organizations or events (e.g., roundtable discussions).\u003c/li\u003e\n\u003cli\u003eThe victim receives an email containing an attachment which, when opened, initiates the RedFlick infection flow.\u003c/li\u003e\n\u003cli\u003eRedFlick executes locally, reducing user friction by requiring only a single interaction compared to legacy ClickFix-based chains.\u003c/li\u003e\n\u003cli\u003eThe infection process configures a scheduled task on the target system to achieve persistence.\u003c/li\u003e\n\u003cli\u003eThe scheduled task executes a command to download and install the CosmicPulse backdoor from actor-controlled infrastructure.\u003c/li\u003e\n\u003cli\u003eThe CosmicPulse backdoor enables remote access, providing the threat actor with persistent entry for cyberespionage objectives.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe evolution to RedFlick and large-scale phishing has enabled Star Blizzard to successfully compromise over 100 organizations across the United States and the United Kingdom. Victims include government officials, think tanks, NGOs, and financial institutions involved in international policy and support for Ukraine. Successful compromise allows the actor to perform persistent cyberespionage, potentially resulting in the exfiltration of sensitive diplomatic, strategic, and financial intelligence.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize hardening against phishing and malicious task creation by implementing the following:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy endpoint detection rules to monitor for suspicious scheduled task creation and execution chains.\u003c/li\u003e\n\u003cli\u003eImplement email filtering controls that block messages originating from known compromised infrastructure and investigate mass-mail patterns.\u003c/li\u003e\n\u003cli\u003eAudit scheduled tasks periodically for unauthorized or unusual commands, specifically looking for tasks spawned from common user document folders.\u003c/li\u003e\n\u003cli\u003eReview network egress logs for connections to unknown domains following the execution of suspicious user-space processes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T19:17:03Z","date_published":"2026-09-29T19:17:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-star-blizzard-redflick/","summary":"Russian state actor Star Blizzard has shifted to large-scale phishing campaigns and adopted the RedFlick delivery technique to deploy the CosmicPulse backdoor via scheduled tasks with minimal user interaction.","title":"Star Blizzard Evolution and RedFlick Malware Delivery Technique","url":"https://feed.craftedsignal.io/briefs/2026-09-star-blizzard-redflick/"}],"language":"en","title":"CraftedSignal Threat Feed - Star-Blizzard","version":"https://jsonfeed.org/version/1.1"}