Russian APT Star Blizzard Adopts New Phishing Tactics

Russian APT Star Blizzard Evolves Phishing with 'RedFlick' Technique

HIGH
October 1, 2026
5m read
Threat ActorPhishingMalware

Related Entities

Threat Actors

Other

CosmicPulse

Full Report

Executive Summary

The Russia-linked Advanced Persistent Threat (APT) group Star Blizzard has refined its phishing tactics to increase the scale and efficiency of its campaigns. According to a September 30, 2026 report from Microsoft Threat Intelligence, the group, also associated with Russia's FSB Centre 18, has shifted from its multi-step "ClickFix" method to a new delivery technique dubbed "RedFlick." This new approach requires only a single click from the victim to deploy the group's custom CosmicPulse backdoor. This evolution has allowed Star Blizzard to broaden its targeting to over one hundred organizations involved in supporting Ukraine, including think tanks, NGOs, and journalists.


Threat Overview

Star Blizzard, also known by aliases such as Callisto Group, Seaborgium, and BlueCharlie, is a threat actor known for its focus on intelligence gathering. Its primary targets are organizations and individuals with expertise on Russia or those involved in international policy and Ukrainian aid efforts.

The group's tactical evolution from "ClickFix" to "RedFlick" represents a significant increase in operational efficiency:

  • Old Tactic (ClickFix): Required multiple interactions from the victim, increasing the chance of failure.
  • New Tactic (RedFlick): A streamlined, single-interaction method that uses scheduled tasks to create a persistent and delayed execution chain for its payload.

This shift lowers the friction for a successful compromise, allowing the group to conduct higher-volume phishing campaigns against a wider set of targets.

Technical Analysis

The "RedFlick" technique is designed for stealth and persistence. The typical attack chain is as follows:

  1. Initial Access: The victim receives a spear-phishing email containing a malicious link. [T1566.002 - Spearphishing Link].
  2. Execution: A single click on the link initiates the infection. This likely triggers the download and execution of an initial-stage script.
  3. Persistence: The script creates a series of scheduled tasks. [T1053.005 - Scheduled Task/Job: Scheduled Task]. This technique allows the malware to persist across reboots and execute its main payload after a delay, potentially evading detection by security tools that monitor for immediate post-exploitation activity.
  4. Payload Delivery: The scheduled tasks eventually download and execute the final payload, the CosmicPulse backdoor.
  5. Command and Control: CosmicPulse, a Python-based backdoor, establishes a C2 channel with Star Blizzard's infrastructure, allowing the attackers to exfiltrate data, execute commands, and deploy further tools. [T1059.006 - Command and Scripting Interpreter: Python].

Impact Assessment

The adoption of the RedFlick technique enables Star Blizzard to conduct more effective and widespread intelligence-gathering operations. For the targeted NGOs, think tanks, and journalists, a successful compromise could lead to the theft of sensitive research, internal communications, source information, and strategic plans related to Ukrainian support efforts. This stolen information could be used by the Russian government for intelligence purposes, to counter policy initiatives, or for disinformation campaigns. The increased scale of attacks means a larger number of organizations are now at risk.


Cyber Observables — Hunting Hints

Security teams can hunt for Star Blizzard activity by looking for the following patterns:

Type
Command Line Pattern
Value
schtasks.exe /create
Description
Monitor for the creation of new scheduled tasks, especially by suspicious processes originating from an email client or web browser.
Type
Process Name
Value
python.exe or pythonw.exe
Description
Look for Python processes running from unusual directories or with suspicious command-line arguments, which could indicate the CosmicPulse backdoor.
Type
Network Traffic Pattern
Value
Outbound connections to unknown or newly registered domains.
Description
The CosmicPulse backdoor will communicate with a C2 server. Monitor for suspicious DNS queries and outbound connections from endpoints.
Type
Log Source
Value
Windows Event ID 4698 (A scheduled task was created)
Description
This event log is a high-fidelity indicator of the RedFlick persistence mechanism.

Detection & Response

Defending against these evolved phishing campaigns requires a combination of technical controls and user awareness.

  1. Email Security Gateway: Use an email security solution to block phishing emails with malicious links. Configure it to scan for known malicious domains and use sandboxing to analyze the behavior of linked content.
  2. Scheduled Task Monitoring: D3-PAM: Process-based Account Monitoring. Actively monitor for the creation of new scheduled tasks (Windows Event ID 4698). Correlate task creation with other suspicious activity, such as a user clicking a link in an email.
  3. Process Auditing: Enable command-line auditing (Event ID 4688) to capture the full command line for all process creations. This can reveal the execution of schtasks.exe or python.exe with malicious parameters.

Mitigation

Strategic mitigations can help defend against Star Blizzard's TTPs.

  1. User Training: D3-UT: User Training. Continuously train high-risk users (like journalists and policy experts) to identify and report sophisticated spear-phishing attempts.
  2. Application Control: D3-EAL: Executable Allowlisting. Use application control policies to restrict the execution of scripting interpreters like python.exe from user-writable directories (e.g., AppData).
  3. Attack Surface Reduction: Block or sandbox content from newly registered domains, as these are often used in phishing campaigns.

Timeline of Events

1
September 30, 2026
Microsoft Threat Intelligence reports on Star Blizzard's new 'RedFlick' phishing technique.
2
October 1, 2026
This article was published

MITRE ATT&CK Mitigations

Educating users, especially high-value targets, on how to spot and report spear-phishing emails is a critical first line of defense.

Use application control to prevent the execution of unauthorized scripts and interpreters like Python from user-writable locations.

Mapped D3FEND Techniques:

Enable and monitor logs for scheduled task creation (Event ID 4698) and process execution with command-line arguments (Event ID 4688) to detect this TTP.

D3FEND Defensive Countermeasures

Since Star Blizzard's RedFlick technique still relies on a user clicking a link, targeted and continuous user training is a vital mitigation. For high-risk individuals in NGOs, think tanks, and journalism, generic annual training is insufficient. These users should receive specialized training on identifying sophisticated spear-phishing campaigns, including sender impersonation and contextually relevant lures. Phishing simulations tailored to their roles should be conducted regularly. Most importantly, a simple and clear process for reporting suspicious emails to the security team must be established and encouraged, allowing for rapid analysis and response.

To directly counter the execution of the CosmicPulse backdoor, organizations should implement application control policies. A powerful strategy is to prevent scripting interpreters like python.exe and powershell.exe from running out of user-writable directories such as %APPDATA% or Downloads. By default, these tools should only be allowed to run from protected system directories (e.g., C:\Windows\System32). This form of execution prevention can break the attack chain even if a user clicks the malicious link, as the downloaded script will be blocked from executing in the user's profile space, thus preventing the backdoor from being installed.

The core of the RedFlick technique is the use of scheduled tasks for persistence. Security teams must actively monitor for the creation of new scheduled tasks. This can be achieved by collecting and analyzing Windows Event ID 4698 ('A scheduled task was created'). A baseline of legitimate scheduled tasks should be established for standard corporate builds. Any new task created outside of a software installation or approved change should trigger an alert. The alert should include the task name, the user context it runs in, and the command it executes. This provides high-fidelity detection of Star Blizzard's persistence mechanism.

Timeline of Events

1
September 30, 2026

Microsoft Threat Intelligence reports on Star Blizzard's new 'RedFlick' phishing technique.

Sources & References

Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
Dark Reading (darkreading.com) •September 30, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

APTStar BlizzardphishingRussiaUkraineFSBCosmicPulse

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.