fieldeffect.com • 2h
Star Blizzard Scales Phishing Operations with RedFlick Malware Delivery
Since January 2026, the Russian state-linked threat actor Star Blizzard has expanded its phishing campaign using large‑volume email lures, compromised web infrastructure, and a novel RedFlick delivery chain that inserts password‑protected ZIP/RAR archives into ongoing trusted email threads, ultimately deploying the CosmicPulse backdoor. Over 100 organizations across ≥13 campaigns in government, diplomacy, research, public policy, journalism, and finance—primarily in the US, UK, and allied NATO states—have been compromised, with single‑victim interaction sufficient for infection and persistence via scheduled tasks, registry Run keys, and service creation.