Russian Threat Actor Star Blizzard Adopted RedFlick
The group shifted tactics to a more stealthy malware delivery technique targeting users across multiple regions.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Do you trust that your organization has sufficient security measures to block modern phishing attempts?
The Russian threat actor Star Blizzard, associated with the Federal Security Service, has transitioned its operations to the RedFlick malware delivery technique. This method aims to increase compromise success rates by reducing required user interaction during infection.
Why it matters
By moving away from older methods like ClickFix, Star Blizzard has significantly scaled its phishing operations beyond its historical focus on Ukraine. The shift demonstrates an ongoing effort to improve evasion and persistence in modern enterprise and personal computing environments.
Microsoft detected 13 large-scale phishing campaigns utilizing RedFlick, a significant expansion of activity following the seizure of 41 domains by the Department of Justice in 2024. The actor has also pivoted to specific malware variants like the DarkSword backdoor targeting iOS devices.
The players
Star Blizzard
A Russian threat actor subordinate to the Federal Security Service Center 18 known for persistent phishing and espionage operations.
Microsoft
A global technology company that manages threat intelligence and security infrastructure across its Windows and cloud ecosystem.
Proofpoint
A cybersecurity firm specializing in enterprise security and compliance that tracks threat actor campaigns.
The details
RedFlick deploys malware by using LNK files, or Windows shortcut files, disguised as legitimate documents to execute MSI installers. These installers create scheduled tasks that use system utilities such as conhost.exe, the Windows Console Host, and cmd.exe to launch the CosmicPulse backdoor with minimal user interaction. In July 2026, the group further refined this infection chain by embedding PowerShell scripts directly within PDF files to initiate the payload process.
Timeline
2017: Star Blizzard began active operations.
2024: Microsoft and the DOJ seized 41 domains.
January 2026: Star Blizzard adopted RedFlick.
March 2026: Phishing expanded beyond Ukraine and targeted iOS devices.
July 2026: The group used PDF-hidden PowerShell payloads.
The Tech Race
The transition to RedFlick follows the 2024 seizure of 41 Star Blizzard domains, proving that infrastructure disruption alone is insufficient to halt the group. This evolution marks a strategic pivot toward higher-evasion techniques, challenging the current defensive playbooks used by security vendors.
Users should be cautious of unexpected LNK or PDF files, as these can execute malicious tasks without clear user prompts. Organizations should monitor for unusual PowerShell activity spawned by PDF or document-related processes to detect potential compromise.
The takeaway
The move to RedFlick highlights how threat actors prioritize minimizing user interaction to bypass modern security controls. Security teams should monitor for the adoption of these specific LNK-to-MSI execution chains by other groups in the coming months.
Further reading
For more on the latest trends in state-sponsored digital espionage, visit our Cybersecurity section.
Live Poll
Do you trust that your organization has sufficient security measures to block modern phishing attempts?






