Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    September 30, 2026

    Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative – NextBigFuture.com

    September 30, 2026

    Samsung Galaxy A18 4G review

    September 30, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
    Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
    Cybersecurity

    Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    The Tech GuyBy The Tech GuySeptember 30, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Russian state-sponsored APT Star Blizzard has updated its tactics, techniques, and procedures (TTPs) in recent attacks to evade detection, Microsoft says.

    Advertisement

    Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted spear-phishing campaigns against academia, defense, governmental organizations, NGOs, and think tanks, and for using the ClickFix technique and the DarkSword iOS exploit kit.

    In attacks observed this year, the APT has been relying on large-scale phishing attacks and a new malware delivery technique dubbed RedFlick, which requires a single user interaction for malware execution.

    If the recipient responds to the initial phishing email, Star Blizzard sends a second message containing a password-protected RAR or ZIP archive that triggers the malware delivery.

    The state-sponsored group has been using the technique in attacks against Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have been providing support to Ukraine.

    Star Blizzard, Microsoft says, has been creating accounts on compromised websites to send tens to hundreds of phishing emails per campaign, likely through a mass-mailing phishing platform.

    Advertisement. Scroll to continue reading.

    Between January and August 2026, the APT launched over a dozen campaigns containing a RedFlick lure attachment, posing either as Ukrainian authorities or a reputable think tank or NGO. The emails were crafted to appear to come from within the targeted organization.

    In January, Star Blizzard began sending phishing emails with a malicious Virtual Hard Disk (VHDX) container attached. Inside, the group embedded the RedFlick payload: a shortcut file disguised as a PDF document that, when clicked, opens a decoy file while quietly executing a background script.

    That script fetches an MSI installer, configures scheduled tasks for persistence, and launches the NoroBot or BaitSwitch downloader to deliver the CosmicPulse Python backdoor.

    In April, Star Blizzard started using three RedFlick scheduled tasks for persistence, masquerading as Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.

    In July, the APT was seen using a multistage execution chain that involved a PowerShell payload executed by the malicious LNK file. The PowerShell attempted to fetch another MSI file that attempted to create two additional scheduled tasks.

    “Star Blizzard’s shift from ClickFix-based delivery chains to VHDX files, expanded use of scheduled tasks for persistence, and concealment of payloads within PDF files demonstrate the actor’s continued ability to adapt their delivery methods in response to evolving defenses,” Microsoft notes.

    Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    Related: Four Cyber Threats Harboring Big Plans for the Future

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    September 30, 2026

    Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

    September 30, 2026

    Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

    September 30, 2026

    OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    September 29, 2026

    RemoteThreat Launches With $7 Million for Offensive Operations Platform

    September 29, 2026

    Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    September 29, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    September 30, 2026

    Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative – NextBigFuture.com

    September 30, 2026

    Samsung Galaxy A18 4G review

    September 30, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.