Tech News
← Home  ·  All topics

Star Blizzard

2 GoKawiil briefs on this topic

Star Blizzard debuts RedFlick delivery method to install CosmicPulse backdoor

Microsoft researchers say the Russian state-linked group Star Blizzard is using a new technique called RedFlick to deploy its CosmicPulse backdoor. The chain starts with phishing emails leading victims to open a VHDX virtual disk containing a disguised LNK file, which triggers hidden commands, a decoy PDF, and an MSI installer that sets up three scheduled tasks to reconnoiter the system and fetch further payloads, including a downloader called NOROBOT/BAITSWITCH that ultimately installs CosmicPulse.

Star Blizzard swaps ClickFix for RedFlick to widen phishing reach

Microsoft Threat Intelligence reported on Sept. 29 that Russia-linked APT group Star Blizzard has replaced its ClickFix social-engineering technique with a new malware delivery method called RedFlick. The group, also known as ColdRiver or Callisto, has used RedFlick since January to install its CosmicPulse backdoor via scheduled tasks, requiring only a single victim interaction instead of multiple steps.