Russian state hackers use new RedFlick technique to push malware

The Russian state-sponsored actor Star Blizzard has been detected using a novel malware-installation method called “RedFlick” to deliver its favored CosmicPulse backdoor.

While the described technique is nothing new, it allows the threat actor to diversify its attack methods and increase the level of automation while reducing the interaction surface with the victim.

Microsoft notes that threat group Star Blizzard has been observed ramping up phishing activities and improving malware-delivery techniques in 2026.

The group, which has been active since 2017, has diversified its attack vectors, utilizing various platforms for payload delivery such as ClickFix and WhatsApp, and has also been noted for its continuous development and deployment of new malware families.

This attack chain begins with spear-phishing emails, for example, an invitation followed by a second message containing a password-protected ZIP or RAR archive.

The archive contains a VHDX virtual disk containing a LNK file disguised as a PDF. When the file is opened, it runs a command in a hidden window, while displaying a decoy PDF to the victim read more about Russian state hackers use new RedFlick technique to push malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *