As reported by Dark Reading, Russia-linked APT actor Star Blizzard has shifted away from its ClickFix social-engineering technique in favor of a newly dubbed method called "RedFlick," designed to broaden its phishing reach against Ukrainian-linked organizations — particularly NGOs, think tanks, and journalists. The end goal remains deployment of the group's CosmicPulse backdoor, a persistence mechanism that enables long-term credential theft and intelligence collection.
Why This Matters
Star Blizzard — also tracked as COLDRIVER, Seaborgium, TA446, and Callisto — is one of the most prolific credential-phishing operators linked to Russia's FSB. The group's targeting pattern is remarkably consistent: individuals and organizations in the information ecosystem surrounding geopolitical flashpoints. What this evolution tells us is not that the group is becoming more sophisticated in a technical sense, but that it is becoming more adaptable. When one social-engineering template loses effectiveness — likely due to public reporting and improved detection — Star Blizzard simply iterates.
The shift from ClickFix to RedFlick is not innovation for its own sake; it is a measured response to defender awareness. The tradecraft cycle here is measured in weeks, not years.
That iterative speed should concern defenders. Many organizations operating in the NGO, journalism, and policy-research sectors lack dedicated security operations teams, threat-intelligence subscriptions, or even basic email-authentication hardening. Star Blizzard is targeting precisely that gap.
Who Is at Risk
The common denominator is not technical exposure — it is information value. If your organization holds insights, contacts, or data that could inform Russian intelligence assessments, you are a target regardless of your security maturity.
The Broader Implication
Star Blizzard's continued operational tempo — despite repeated public attributions by Microsoft, Google, Mandiant, and Western governments — reinforces a sobering reality: public naming and shaming does not deter state-sponsored operators whose missions are deemed strategically important. The FSB appears content to absorb reputational cost in exchange for continued access to high-value information streams.
Furthermore, the pivot to RedFlick suggests the group is actively A/B-testing its lures. This is product-thinking applied to espionage. Defenders should expect further iterations — RedFlick will not be the last variant.
What You Should Do — Shield53 Recommendations
Immediate Actions
- Assess email-security posture: Verify DMARC is enforced at
p=reject, SPF and DKIM are properly configured, and spoofed-display-name alerts are enabled in your email gateway - Deploy phishing-resistant MFA: Move away from SMS and TOTP-based authentication toward FIDO2/WebAuthn hardware keys for high-risk personnel — especially those in communications, research, or leadership roles
- Brief at-risk staff: Conduct targeted awareness training for individuals whose job titles or public profiles map to Star Blizzard's known targeting pattern. Generic phishing training is insufficient here
- Hunt for CosmicPulse indicators: Review endpoint telemetry for unusual persistence mechanisms, unexpected scheduled tasks, or anomalous outbound connections to newly registered domains
Longer-Term Hardening
- Implement conditional access policies that restrict authentication from unexpected geographies or unmanaged devices
- Subscribe to threat-intelligence feeds that specifically track Star Blizzard infrastructure and lure patterns — the group's TTPs are well-documented and shareable across ISAC communities
- Establish a reporting channel for suspicious contacts: many Star Blizzard campaigns begin via LinkedIn or other professional networking platforms, not email. Staff must know how to flag unusual outreach
- Segment sensitive communications: Ensure that research contacts, source lists, and draft publications are stored with access controls that limit lateral movement if a single account is compromised
Organizations in the civil society and media sectors should treat Star Blizzard as an active, persistent, and patient adversary — not a periodic nuisance. The group's willingness to invest weeks or months in building rapport with a target before delivering a payload means that defensive vigilance must be sustained, not reactive.