Microsoft says Star Blizzard is using RedFlick to spread CosmicPulse malware
The new delivery chain reduces victim interaction and has already been used in at least 13 phishing campaigns against more than 100 organisations.
Microsoft says the Russian state-linked group Star Blizzard has adopted a new delivery chain called RedFlick to push its CosmicPulse backdoor with less victim interaction and more automation. The campaign starts with phishing and a booby-trapped archive, then uses a disguised shortcut, scheduled tasks, and a downloader chain to fetch and decode the payload. Microsoft says the group has used this approach in at least 13 large-scale phishing campaigns since the start of the year, affecting more than 100 organizations, mostly in the United States and the United Kingdom. The targeted victims include Ukrainian individuals and institutions, along with NGOs, think tanks, governments, and financial institutions that have backed Ukraine. Microsoft advises phishing-resistant authentication, Conditional Access, stronger email controls, independent verification of suspicious requests, and EDR block mode.
Why it matters
The shift to a more automated chain makes the group’s campaigns easier to run at scale and harder to interrupt once phishing succeeds. That broadens the risk for Ukrainian individuals and institutions, as well as NGOs, think tanks, governments and financial institutions that have supported Ukraine, especially in the US and UK. Microsoft’s guidance shows the practical response is to tighten identity, email and endpoint controls and to verify suspicious requests out of band.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer