Since January 2026, Microsoft has observed Russian state actor Star Blizzard evolve their detection evasion capabilities via large-scale phishing campaigns, the use of accounts on compromised websites, and a new malware delivery technique called RedFlick.
msft.it/6010actya
RedFlick can enable CosmicPulse malware installation after a single user interaction, reducing friction in the compromise process. Combined with the actor’s updated tactics, techniques, and procedures (TTPs), these changes improve Star Blizzard’s ability to reach more targets and increase the likelihood of successful compromise
These developments reflect the actor’s continued efforts to streamline malware deployment and scale operations to support ongoing cyberespionage objectives. Get detections, indicators of compromise (IOCs), and hunting guidance from this Microsoft Threat Intelligence blog post.