< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom, Ukraine · 3 sources

started · updated

Star Blizzard hackers scale up phishing attacks using RedFlick technique

Russian state-sponsored hacking group Star Blizzard, which is linked to the Russian Federal Security Service (FSB), has significantly expanded its cyberattack operations. According to Microsoft, the group has transitioned from highly targeted spear-phishing to larger-scale campaigns using mass-mailing platforms to reach hundreds of potential victims.

A key development is the use of a new malware delivery technique called ‘RedFlick’. This method involves sending password-protected archives that, upon user interaction, execute background scripts to deploy malware such as NoroBot or BaitSwitch. The group has also been observed creating accounts on compromised websites to impersonate reputable organizations.

The attacks have targeted over 100 organizations, primarily in the United States and the United Kingdom. The primary targets include Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that provide political or financial support to Ukraine.

Entities

FSB · Star Blizzard