NEWS

Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

FSB-linked Star Blizzard dropped ClickFix for a one-click 'RedFlick' chain, expanding phishing beyond Ukraine to deploy its CosmicPulse backdoor.

Dylan H.

News Desk

September 30, 2026
8 min read
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Star Blizzard Trades a Clunky Lure for a One-Click Infection Chain

Russia's FSB-linked Star Blizzard — active since 2017 and previously disrupted by Microsoft and U.S. and U.K. officials in a 2024 takedown of its operational infrastructure — has overhauled its phishing tradecraft to cast a wider net, according to a September 29, 2026 blog post from Microsoft Threat Intelligence (MTI), reported first by Dark Reading. The group, long known for targeting journalists, NGOs, and Russia experts who support Ukraine, has retired its multi-step ClickFix social-engineering lure in favor of a new delivery technique Microsoft calls RedFlick — an infection chain that needs only a single victim interaction to drop the group's custom CosmicPulse backdoor, down from the several deliberate actions ClickFix demanded. Since January 2026, Star Blizzard has run more than a dozen RedFlick campaigns against over 100 organizations, concentrated in the United States and United Kingdom, frequently impersonating recognizable names such as the Atlantic Council and Chatham House to lend its fake event invitations credibility.


AttributeValue
Threat actorStar Blizzard (FSB Center 18-linked)
Also tracked asSEABORGIUM, Callisto Group, TA446, COLDRIVER
Active since2017
Prior disruptionMicrosoft- and government-led takedown of Star Blizzard infrastructure, 2024
Retired tacticClickFix — fake-CAPTCHA lure requiring multiple victim actions
New tacticRedFlick — single-interaction phishing/malware-delivery chain
PayloadCosmicPulse — custom Python-based backdoor
Campaign windowJanuary 2026 – present (12+ campaigns)
Scale100+ organizations targeted, mostly in the US and UK
Impersonated luresAtlantic Council, Chatham House, Ukrainian government bodies
Primary targetsJournalists, NGOs, think tanks, Russia experts, Ukraine-linked organizations
DisclosureMicrosoft Threat Intelligence blog, September 29, 2026

From Multi-Step ClickFix to a Single Click

Through much of 2025, Star Blizzard's go-to initial-access method was ClickFix — a fake CAPTCHA or "verify you're human" page that walks a target through manually opening a Run dialog or terminal and pasting in attacker-supplied text. Every one of those steps was a chance for a cautious user or an endpoint control to break the chain. According to Microsoft, RedFlick removes that friction almost entirely: once a target opens the malicious attachment, the rest of the chain — fetching an installer, registering scheduled tasks, and launching CosmicPulse — runs silently in the background. Microsoft's blog states plainly that "the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process," which the company frames as a deliberate trade of complexity for conversion rate.

A Two-Stage Social Engineering Play

Unlike a blind mass-mail blast, Star Blizzard's RedFlick campaigns often unfold in two steps designed to build false rapport before the payload ever appears. The first email is typically an innocuous-looking invitation — to a conference, panel, or briefing — sent from an account impersonating a known institution. Only if the recipient replies does Star Blizzard send a follow-up message carrying a password-protected RAR or ZIP archive, framed as event materials or an agenda. That second-stage archive is what actually triggers the RedFlick delivery chain, a sequencing choice that helps the lure slip past automated scanning of unsolicited first-contact attachments and relies on the human instinct to trust a conversation already in progress.

Named-Brand Lures and the "Testing Ground" Theory

Microsoft's researchers found RedFlick invitations spoofing or referencing well-known organizations — including the Atlantic Council and Chatham House — as well as Ukrainian government bodies, with many messages crafted to look as though they originated from inside the target's own organization. Notably, while Star Blizzard's RedFlick campaigns began narrowly focused on Ukraine-linked individuals and institutions, Microsoft has since observed the targeting expand to journalists and NGOs well beyond that original scope. CyberScoop, citing Microsoft's assessment, reported the theory that "the actor's shift from Ukraine-focused operations to global targets could indicate Star Blizzard initially targeted Ukraine to test their new capabilities" before rolling RedFlick out more broadly — consistent with the group's history of using Ukraine-adjacent targets as a proving ground for tradecraft it later points at a wider victim pool.

CosmicPulse: The Payload Underneath

Regardless of which RedFlick variant delivers it, the end state is the same: CosmicPulse, a Python-based backdoor that gives Star Blizzard a persistent foothold on the compromised Windows host. The chain reaches CosmicPulse via intermediate downloaders — Microsoft has named NoroBot and BaitSwitch in earlier reporting on the same campaign set — and leans on legitimate, built-in Windows functionality (scheduled tasks, PowerShell, and similar system utilities) rather than any software vulnerability, which is consistent with Star Blizzard's long-running preference for living-off-the-land techniques over exploit development.


Impact Assessment

Impact AreaDescription
Reduced attacker frictionA single click now suffices where ClickFix needed several deliberate victim actions, raising the odds any given lure succeeds
Expanded targeting scopeJournalists and NGOs with no direct Ukraine portfolio are now in scope, not just the group's traditional Ukraine-linked victim set
Credibility abuseSpoofing recognized institutions like the Atlantic Council and Chatham House increases the chance a target engages before scrutinizing the sender
Detection evasionThe two-stage, reply-gated delivery of a password-protected archive helps the payload bypass automated scanning of unsolicited attachments
Resilience after disruptionA 2024 takedown of Star Blizzard infrastructure did not end the group's operations — it re-emerged with retooled tradecraft within roughly a year
Espionage riskSuccessful CosmicPulse infections give an FSB-linked actor a persistent backdoor into the communications of press, NGO, and policy-research staff

Recommendations

For Journalists, NGOs, and Think Tank Staff

  • Treat unsolicited event invitations — especially ones that lead to a second email with a password-protected archive — as high-risk until verified through a separate, known channel.
  • Be skeptical of invitations referencing well-known institutions such as the Atlantic Council or Chatham House; verify directly with the organization before opening any attachment tied to the invite.
  • Never run commands in a Run dialog or terminal based on instructions from an email or website, and report suspected RedFlick-style lures to IT or security staff immediately.

For Security Teams

  • Hunt for Microsoft's published RedFlick and CosmicPulse indicators and detections (including CosmicPulse's Python backdoor signatures) across endpoint telemetry.
  • Flag inbound mail threads where a benign first email is followed by a password-protected RAR or ZIP attachment, particularly from first-contact senders claiming to represent conferences, panels, or briefings.
  • Apply attachment controls that sandbox or strip password-protected archives arriving via email, since standard scanning cannot inspect encrypted contents.
  • Assume a prior disruption of an APT's infrastructure does not retire the group — monitor for retooled tradecraft from previously sanctioned or indicted actors.

For Communications and Events Teams

  • Establish an out-of-band verification step (phone call or known contact) before staff reply to or forward event-related attachments from outside senders, even ones appearing to reference familiar institutions.
  • Brief staff who regularly receive conference and briefing invitations — a population disproportionately targeted by this campaign — on the two-stage RedFlick lure pattern specifically.

Key Takeaways

  1. Star Blizzard, an FSB-linked Russian APT active since 2017, has replaced its multi-step ClickFix lure with a new, lower-friction technique Microsoft calls RedFlick.
  2. RedFlick needs only a single user interaction to deploy the group's CosmicPulse Python backdoor, compared to several deliberate steps required under ClickFix.
  3. Since January 2026, Star Blizzard has run 12+ RedFlick campaigns against 100+ organizations, mostly in the US and UK.
  4. Targeting has expanded beyond the group's traditional Ukraine-linked focus to include journalists and NGOs more broadly, which Microsoft suggests may reflect Ukraine being used as an initial testing ground for the new tradecraft.
  5. Campaigns often use a two-stage approach — an innocuous first email followed by a reply-gated, password-protected archive — and impersonate recognizable names like the Atlantic Council and Chatham House.
  6. The group's resurgence with retooled tactics roughly a year after a 2024 disruption of its infrastructure underscores that takedowns alone do not permanently neutralize a well-resourced, state-linked actor.

Sources