Star Blizzard Expands Phishing Campaigns Using RedFlick Malware Delivery Technique
Russian state-sponsored threat actor Star Blizzard has targeted over 100 organizations using a sophisticated phishing campaign combined with a novel malware delivery method called RedFlick, which abuses Windows scheduled tasks to install the CosmicPulse backdoor. The root cause lies in insufficient user security awareness and a failure to detect and block advanced phishing lures before they reach end users. Once delivered, the scheduled task persistence mechanism allows attackers to maintain long-term footholds that can go undetected without robust endpoint and behavioral monitoring. This attack demonstrates that nation-state adversaries continuously evolve their tactics, making both human vigilance and technical detection controls critical layers of defense.
Tactical Insight
Immediate actions
- Deploy advanced email filtering and anti-phishing solutions capable of detecting credential harvesting and malicious link patterns used by sophisticated threat actors.
- Audit all scheduled tasks across endpoints and servers to identify unauthorized or suspicious entries indicative of RedFlick-style persistence mechanisms.
- Issue targeted user awareness alerts to staff in high-risk sectors (government, defense, NGOs) warning of Star Blizzard spear-phishing techniques.
Long-term improvements
- Establish a continuous phishing simulation and security awareness training program tailored to nation-state threat actor TTPs.
- Implement application allowlisting and restrict the ability of non-administrative users to create or modify scheduled tasks via Group Policy.
- Adopt a Zero Trust architecture to limit lateral movement opportunities if an initial phishing compromise succeeds.
Detection measures
- Enable behavioral detection rules in your EDR/SIEM to flag anomalous scheduled task creation, especially those invoking PowerShell, scripts, or unknown binaries.
- Monitor outbound network traffic for beaconing patterns consistent with the CosmicPulse backdoor's command-and-control communication.
- Subscribe to threat intelligence feeds (e.g., CISA advisories, Microsoft MSTIC) for real-time indicators of compromise related to Star Blizzard campaigns.