Back to all lessons
Awareness Lessons
6 days ago

Star Blizzard Expands Phishing Campaigns Using RedFlick Malware Delivery Technique

Russian state-sponsored threat actor Star Blizzard has targeted over 100 organizations using a sophisticated phishing campaign combined with a novel malware delivery method called RedFlick, which abuses Windows scheduled tasks to install the CosmicPulse backdoor. The root cause lies in insufficient user security awareness and a failure to detect and block advanced phishing lures before they reach end users. Once delivered, the scheduled task persistence mechanism allows attackers to maintain long-term footholds that can go undetected without robust endpoint and behavioral monitoring. This attack demonstrates that nation-state adversaries continuously evolve their tactics, making both human vigilance and technical detection controls critical layers of defense.

Tactical Insight

Immediate actions

  • Deploy advanced email filtering and anti-phishing solutions capable of detecting credential harvesting and malicious link patterns used by sophisticated threat actors.
  • Audit all scheduled tasks across endpoints and servers to identify unauthorized or suspicious entries indicative of RedFlick-style persistence mechanisms.
  • Issue targeted user awareness alerts to staff in high-risk sectors (government, defense, NGOs) warning of Star Blizzard spear-phishing techniques.

Long-term improvements

  • Establish a continuous phishing simulation and security awareness training program tailored to nation-state threat actor TTPs.
  • Implement application allowlisting and restrict the ability of non-administrative users to create or modify scheduled tasks via Group Policy.
  • Adopt a Zero Trust architecture to limit lateral movement opportunities if an initial phishing compromise succeeds.

Detection measures

  • Enable behavioral detection rules in your EDR/SIEM to flag anomalous scheduled task creation, especially those invoking PowerShell, scripts, or unknown binaries.
  • Monitor outbound network traffic for beaconing patterns consistent with the CosmicPulse backdoor's command-and-control communication.
  • Subscribe to threat intelligence feeds (e.g., CISA advisories, Microsoft MSTIC) for real-time indicators of compromise related to Star Blizzard campaigns.