Microsoft has reported that the Russian state-backed Advanced Persistent Threat (APT) group, known as Star Blizzard, has modernized its attack strategies to better avoid detection. This group, associated with the Russian Federal Security Service’s Centre 18, is recognized for its sophisticated spear-phishing operations targeting various sectors, including academia, defense, and governmental entities.
Enhanced Tactics and New Malware
In recent incidents, Star Blizzard has deployed large-scale phishing campaigns, introducing a novel malware technique identified as RedFlick. This method demands a single action from the user to initiate malware execution. The strategy involves sending a follow-up email with a password-protected archive, which activates the malware when opened.
The group has been particularly aggressive towards Ukrainian entities and international organizations that support Ukraine. They leverage compromised websites to disseminate vast numbers of phishing emails, likely through automated phishing platforms.
Phishing Campaigns and Malware Deployment
Between January and August 2026, Star Blizzard conducted over a dozen campaigns using RedFlick, masquerading as communications from Ukrainian authorities or reputable institutions. These emails were crafted to seem internally sourced from within the targeted organizations.
In January, the group began utilizing malicious Virtual Hard Disk containers in their phishing emails. These containers hid the RedFlick payload within a shortcut file disguised as a PDF, which, when activated, covertly launched a script fetching further malware components like NoroBot or BaitSwitch.
Adaptation and Persistence Techniques
By April, the group enhanced persistence through the use of scheduled tasks, camouflaged as legitimate system processes. In July, they advanced to a multistage execution chain involving PowerShell scripts to fetch additional malware components.
Microsoft highlights Star Blizzard’s shift from traditional delivery methods to more sophisticated techniques as evidence of their agility in adapting to security defenses. This evolution underscores the persistent threat they pose to global cybersecurity.
As these threats continue to evolve, organizations are urged to bolster their cybersecurity measures, remain vigilant, and stay informed about the latest tactics employed by such groups.
