Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics

Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics

Posted on September 30, 2026 By CWS

Microsoft has reported that the Russian state-backed Advanced Persistent Threat (APT) group, known as Star Blizzard, has modernized its attack strategies to better avoid detection. This group, associated with the Russian Federal Security Service’s Centre 18, is recognized for its sophisticated spear-phishing operations targeting various sectors, including academia, defense, and governmental entities.

Enhanced Tactics and New Malware

In recent incidents, Star Blizzard has deployed large-scale phishing campaigns, introducing a novel malware technique identified as RedFlick. This method demands a single action from the user to initiate malware execution. The strategy involves sending a follow-up email with a password-protected archive, which activates the malware when opened.

The group has been particularly aggressive towards Ukrainian entities and international organizations that support Ukraine. They leverage compromised websites to disseminate vast numbers of phishing emails, likely through automated phishing platforms.

Phishing Campaigns and Malware Deployment

Between January and August 2026, Star Blizzard conducted over a dozen campaigns using RedFlick, masquerading as communications from Ukrainian authorities or reputable institutions. These emails were crafted to seem internally sourced from within the targeted organizations.

In January, the group began utilizing malicious Virtual Hard Disk containers in their phishing emails. These containers hid the RedFlick payload within a shortcut file disguised as a PDF, which, when activated, covertly launched a script fetching further malware components like NoroBot or BaitSwitch.

Adaptation and Persistence Techniques

By April, the group enhanced persistence through the use of scheduled tasks, camouflaged as legitimate system processes. In July, they advanced to a multistage execution chain involving PowerShell scripts to fetch additional malware components.

Microsoft highlights Star Blizzard’s shift from traditional delivery methods to more sophisticated techniques as evidence of their agility in adapting to security defenses. This evolution underscores the persistent threat they pose to global cybersecurity.

As these threats continue to evolve, organizations are urged to bolster their cybersecurity measures, remain vigilant, and stay informed about the latest tactics employed by such groups.

Security Week News Tags:Cybersecurity, Defense, FSB, Microsoft, NGOs, phishing attacks, RedFlick Malware, Russian APT, Star Blizzard, Ukraine

Post navigation

Previous Post: Hackers Exploit ChatGPT with ClickFix to Spread RAT

Related Posts

ThreatLocker Secures 0M in Series F Funding ThreatLocker Secures $190M in Series F Funding Security Week News
Reach Security Raises  Million for Exposure Management Solution Reach Security Raises $10 Million for Exposure Management Solution Security Week News
Urgent Advisory: Exchange Server Zero-Day Exploited Urgent Advisory: Exchange Server Zero-Day Exploited Security Week News
Cisco Resolves Critical Flaws in Enterprise Solutions Cisco Resolves Critical Flaws in Enterprise Solutions Security Week News
Critical Docker AI Flaw Enables RCE and Data Breaches Critical Docker AI Flaw Enables RCE and Data Breaches Security Week News
Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
  • Hackers Exploit ChatGPT with ClickFix to Spread RAT
  • SectopRAT Variant Concealed in Windows Software Unveiled
  • Critical NetScaler Zero-Day Exploits Impacting Key Sectors
  • Critical Vulnerability in Cisco SD-WAN Manager Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
  • Hackers Exploit ChatGPT with ClickFix to Spread RAT
  • SectopRAT Variant Concealed in Windows Software Unveiled
  • Critical NetScaler Zero-Day Exploits Impacting Key Sectors
  • Critical Vulnerability in Cisco SD-WAN Manager Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark