Full Report
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.
Analysis Summary
# Threat Actor: Star Blizzard
## Attribution & Identity
* **Actor Identification:** Star Blizzard is a Russian state-sponsored threat actor.
* **Aliases:** SEABORGIUM, COLDRIVER, Callisto Group, TA446.
* **Known Associations:** Attributed to the Russian Federal Security Service (FSB).
## Activity Summary
Since January 2026, Star Blizzard has significantly evolved its operational tradecraft. The actor shifted from highly targeted, bespoke social engineering to large-scale phishing campaigns. The most notable development is the adoption of the **RedFlick** malware delivery technique, which replaced their previous "ClickFix" infection chains. These 2026 operations focus on cyberespionage, primarily targeting entities supporting Ukraine or involved in Western international policy.
## Tactics, Techniques & Procedures
* **Social Engineering:** Large-scale phishing campaigns using lures related to international conferences (e.g., URC 2026) and policy discussions.
* **Detection Evasion:** Use of compromised website accounts to host malicious content and the use of legitimate services to blend in with normal traffic.
* **RedFlick Technique:** A novel delivery method that initiates a series of scheduled tasks to deploy payloads, requiring only a single user interaction (reducing victim friction).
* **Persistence:** Use of scheduled tasks to maintain presence and execute payloads.
* **Payload Delivery:** Use of PowerShell installers and MSI files to download and execute second-stage backdoors.
## Targeting
* **Sectors:** Governments, Western think tanks, Non-Governmental Organizations (NGOs), and international policy institutions.
* **Geography:** Ukraine, Western Europe, and North America (nations with a nexus in supporting Ukraine).
* **Victims:** Ukrainian individuals and institutions, international policy researchers, and civil society organizations (CSOs).
## Tools & Infrastructure
* **Malware:**
* **CosmicPulse:** The actor’s custom backdoor used for persistent access and data exfiltration.
* **RedFlick:** A specialized delivery mechanism/installer.
* **Infrastructure:**
* **Domains:**
* `guach[.]net` (RedFlick PowerShell host)
* `ruten[.]observer` (CosmicPulse downloader DLL)
* `byveo[.]org` (RedFlick PowerShell host)
* `secure-dns-hub[.]com` (CosmicPulse downloader DLL)
* `qumel[.]link` (CosmicPulse downloader DLL)
* `cyrna[.]top` (RedFlick MSI host)
* `drasw[.]club` (CosmicPulse downloader DLL)
* **IP Addresses:**
* `103.160.59[.]97` (CosmicPulse downloader DLL host)
## Implications
The shift toward large-scale phishing and the streamlined RedFlick infection chain indicates an increase in the actor's operational tempo and technical maturity. By reducing the number of steps required for a successful compromise, Star Blizzard has increased the probability of infecting high-value targets. Their continued focus on Ukraine-related policy suggests they remain a primary intelligence-gathering arm for the Russian state regarding geopolitical strategy.
## Mitigations
* **Phishing Defense:** Implement advanced email filtering and attachment sandboxing to identify malicious MSI or PowerShell-based installers.
* **Endpoint Monitoring:** Monitor for unusual scheduled task creation, particularly those executing PowerShell or calling DLLs from temporary directories.
* **Credential Protection:** Enforce phishing-resistant Multi-Factor Authentication (MFA), such as FIDO2-based security keys, to mitigate credential theft attempts.
* **Host-Based Controls:** Restrict the execution of PowerShell and MSI files from untrusted sources or common web-download locations.