Russian state hackers use new RedFlick technique to push malware
The Russian state-sponsored actor Star Blizzard has been detected using a novel malware-installation method called “RedFlick” to deliver its favored CosmicPulse backdoor.
While the described technique is nothing new, it allows the threat actor to diversify its attack methods and increase the level of automation while reducing the interaction surface with the victim.
Microsoft notes that threat group Star Blizzard has been observed ramping up phishing activities and improving malware-delivery techniques in 2026.
The group, which has been active since 2017, has diversified its attack vectors, utilizing various platforms for payload delivery such as ClickFix and WhatsApp, and has also been noted for its continuous development and deployment of new malware families.
This attack ch...










