Microsoft: APT Star Blizzard shifts to RedFlick infection chain
Russia-linked APT Star Blizzard has moved away from ClickFix to a new RedFlick delivery technique using VHDX attachments that need a single user click. Microsoft observed over a dozen campaigns from January to August 2026 targeting Ukraine, NGOs, think tanks and financial institutions.
- RedFlick needs a single user interaction to execute malware
- Over a dozen RedFlick lure campaigns ran from January to August 2026
- The chain delivers NoroBot or BaitSwitch downloaders and the CosmicPulse backdoor
- Since April, three scheduled tasks masquerade as system utilities for persistence
Read next
Security