$ techbeacon▋
Phishing

Russian APT Group Star Blizzard Expands Phishing Campaign with New ‘RedFlick’ Tactic

Russian APT Group Star Blizzard Expands Phishing Campaign with New ‘RedFlick’ Tactic

Russian cyber‑espionage unit known as Star Blizzard has introduced a fresh phishing approach dubbed “RedFlick,” which is being used to install its CosmicPulse backdoor on computers belonging to Ukrainian‑linked non‑governmental organisations, policy think tanks and journalists.

According to researchers who first documented the method, RedFlick blends conventional email‑based lures with specially crafted malicious payloads that trigger the backdoor once a recipient interacts with a link or attachment. The technique is designed to broaden the group’s attack surface by exploiting the trust relationships common in civil‑society networks.

Star Blizzard, also identified in the security community as APT28 or Fancy Bear, has a long history of targeting government agencies, military institutions and mainstream media on behalf of Russian intelligence services. The shift toward NGOs and media outlets that monitor the conflict in Ukraine reflects a strategic emphasis on gathering intelligence from sources that can shape public discourse and policy.

The deployment of CosmicPulse enables the adversary to maintain persistent access, exfiltrate documents and potentially manipulate communications. For organisations that often operate with limited cybersecurity resources, the intrusion poses a risk to donor information, research data and the safety of journalists covering sensitive topics.

Cyber‑security firms and national authorities have responded by issuing advisories that stress rigorous email hygiene, the use of multi‑factor authentication and the rapid deployment of patches for known vulnerabilities. They also recommend sharing indicators of compromise across industry groups to accelerate detection.

Analysts say the emergence of RedFlick underscores the evolving nature of Russia’s digital campaign against Ukraine‑related actors. Ongoing monitoring will be essential to map the full scope of the operation and to inform defensive measures for at‑risk civil‑society entities.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related