The Russia-linked Advanced Persistent Threat (APT) group Star Blizzard has refined its phishing tactics to increase the scale and efficiency of its campaigns. According to a September 30, 2026 report from Microsoft Threat Intelligence, the group, also associated with Russia's FSB Centre 18, has shifted from its multi-step "ClickFix" method to a new delivery technique dubbed "RedFlick." This new approach requires only a single click from the victim to deploy the group's custom CosmicPulse backdoor. This evolution has allowed Star Blizzard to broaden its targeting to over one hundred organizations involved in supporting Ukraine, including think tanks, NGOs, and journalists.
Star Blizzard, also known by aliases such as Callisto Group, Seaborgium, and BlueCharlie, is a threat actor known for its focus on intelligence gathering. Its primary targets are organizations and individuals with expertise on Russia or those involved in international policy and Ukrainian aid efforts.
The group's tactical evolution from "ClickFix" to "RedFlick" represents a significant increase in operational efficiency:
This shift lowers the friction for a successful compromise, allowing the group to conduct higher-volume phishing campaigns against a wider set of targets.
The "RedFlick" technique is designed for stealth and persistence. The typical attack chain is as follows:
T1566.002 - Spearphishing Link].T1053.005 - Scheduled Task/Job: Scheduled Task]. This technique allows the malware to persist across reboots and execute its main payload after a delay, potentially evading detection by security tools that monitor for immediate post-exploitation activity.T1059.006 - Command and Scripting Interpreter: Python].The adoption of the RedFlick technique enables Star Blizzard to conduct more effective and widespread intelligence-gathering operations. For the targeted NGOs, think tanks, and journalists, a successful compromise could lead to the theft of sensitive research, internal communications, source information, and strategic plans related to Ukrainian support efforts. This stolen information could be used by the Russian government for intelligence purposes, to counter policy initiatives, or for disinformation campaigns. The increased scale of attacks means a larger number of organizations are now at risk.
Security teams can hunt for Star Blizzard activity by looking for the following patterns:
schtasks.exe /createpython.exe or pythonw.exeDefending against these evolved phishing campaigns requires a combination of technical controls and user awareness.
schtasks.exe or python.exe with malicious parameters.Strategic mitigations can help defend against Star Blizzard's TTPs.
python.exe from user-writable directories (e.g., AppData).Educating users, especially high-value targets, on how to spot and report spear-phishing emails is a critical first line of defense.
Use application control to prevent the execution of unauthorized scripts and interpreters like Python from user-writable locations.
Mapped D3FEND Techniques:
Since Star Blizzard's RedFlick technique still relies on a user clicking a link, targeted and continuous user training is a vital mitigation. For high-risk individuals in NGOs, think tanks, and journalism, generic annual training is insufficient. These users should receive specialized training on identifying sophisticated spear-phishing campaigns, including sender impersonation and contextually relevant lures. Phishing simulations tailored to their roles should be conducted regularly. Most importantly, a simple and clear process for reporting suspicious emails to the security team must be established and encouraged, allowing for rapid analysis and response.
To directly counter the execution of the CosmicPulse backdoor, organizations should implement application control policies. A powerful strategy is to prevent scripting interpreters like python.exe and powershell.exe from running out of user-writable directories such as %APPDATA% or Downloads. By default, these tools should only be allowed to run from protected system directories (e.g., C:\Windows\System32). This form of execution prevention can break the attack chain even if a user clicks the malicious link, as the downloaded script will be blocked from executing in the user's profile space, thus preventing the backdoor from being installed.
The core of the RedFlick technique is the use of scheduled tasks for persistence. Security teams must actively monitor for the creation of new scheduled tasks. This can be achieved by collecting and analyzing Windows Event ID 4698 ('A scheduled task was created'). A baseline of legitimate scheduled tasks should be established for standard corporate builds. Any new task created outside of a software installation or approved change should trigger an alert. The alert should include the task name, the user context it runs in, and the command it executes. This provides high-fidelity detection of Star Blizzard's persistence mechanism.
Microsoft Threat Intelligence reports on Star Blizzard's new 'RedFlick' phishing technique.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.