Skip to content
Tech News
← Back to articles

Star Blizzard swaps ClickFix for RedFlick to widen phishing reach

read original get YubiKey 5 NFC Security Key → more articles
GoKawiil Brief

Microsoft Threat Intelligence reported on Sept. 29 that Russia-linked APT group Star Blizzard has replaced its ClickFix social-engineering technique with a new malware delivery method called RedFlick. The group, also known as ColdRiver or Callisto, has used RedFlick since January to install its CosmicPulse backdoor via scheduled tasks, requiring only a single victim interaction instead of multiple steps.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Microsoft suggests the simplified infection process, combined with a shift to larger-scale phishing campaigns, could make Star Blizzard's attacks more successful and harder to detect. Given the group's history of targeting journalists, NGOs, and Russia experts tied to Ukraine, the change may signal an effort to compromise more victims with less friction, according to Microsoft's analysis.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — Given nation-state phishing actors like Star Blizzard specifically target journalists, NGOs, and activists with credential-harvesting campaigns, hardware-based authentication is one of the strongest defenses available. A YubiKey adds phishing-resistant multi-factor authentication to email and cloud accounts, making stolen passwords far less useful to attackers.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: darkreading.com — Elizabeth Montalbano, 2026-09-30

Published there as: “Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.