Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Refract AI Intelligence Digest

BLUF

Star Blizzard has evolved its attack chain, replacing ClickFix with RedFlick phishing campaigns against Ukrainian-linked organizations.

NEWS

The Russian APT group Star Blizzard is deploying a new social engineering tactic named RedFlick to bypass previous defenses. This campaign specifically targets NGOs, think tanks, and journalists linked to Ukraine to deliver the CosmicPulse backdoor.

Why I Care

This matters because it expands the attack surface for critical civil society groups already under pressure. Failure to detect RedFlick could lead to espionage and compromised communications within sensitive geopolitical sectors.

Next Steps

Security teams should update email filters to detect RedFlick indicators immediately. Organizations supporting Ukrainian interests must conduct phishing awareness training and audit endpoint detection rules for CosmicPulse signatures.

The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
Back to Blog Listing

Source: Dark Reading ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.