Skip to main content

Star Blizzard refines phishing and malware delivery with the RedFlick technique

0
Medium
Published: 09/30/2026 (09/30/2026, 18:56:02 UTC)
Source: AlienVault OTX General

Description

Since January 2026, the Russian state-sponsored threat actor Star Blizzard has enhanced its phishing and malware delivery methods using a novel technique called RedFlick. This evolution includes large-scale phishing campaigns and leveraging compromised website accounts to evade detection. The actor targets Ukrainian individuals and institutions, as well as international NGOs, Western think tanks, governments, and organizations involved in international policy, especially those supporting Ukraine.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 19:20:46 UTC

Technical Analysis

Microsoft has observed that Star Blizzard, a Russian state threat actor, has refined its operational tradecraft by adopting the RedFlick malware delivery technique alongside large-scale phishing campaigns and the use of compromised website accounts. These tactics improve detection evasion and support ongoing cyberespionage activities. The targeting focuses on Ukrainian entities and international organizations connected to Ukraine support. Indicators include multiple malicious domains, file hashes, and an IP address associated with the campaign. No CVE or specific software vulnerabilities are identified.

Potential Impact

The threat actor's improved phishing and malware delivery capabilities increase the risk of successful cyberespionage against targeted individuals and organizations. This can lead to unauthorized access, data theft, and intelligence gathering, particularly affecting Ukrainian-related entities and international policy organizations. There is no indication of widespread exploitation beyond these targeted campaigns.

Defensive Guidance

No official patches or fixes are applicable as this is a threat actor's campaign rather than a software vulnerability. Organizations should apply targeted defenses against phishing and malware, including monitoring for the listed indicators of compromise (domains, hashes, IPs), employing email filtering, and user awareness training focused on phishing threats. Microsoft’s advisory should be consulted for updates. There is no indication that the threat is mitigated or requires no action.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/"]
Adversary
Star Blizzard
Pulse Id
6abd5b434cf09d69f0ee2e48

Indicators of Compromise

Domain

ValueDescriptionCopy
domaingroy.cc
—
domainmuvb.net
—
domainbpdaersa.click
—
domainmatjk.click
—
domainsecure-dns-hub.com
—
domainqumel.link
—
domainruten.observer
—
domainbyveo.org
—
domainguach.net
—
domainstuseamandesilt.org
—
domainetia.ca
—
domaingliderrompercycl.com
—
domaindivekickspolic.org
—
domaincyrna.top
—
domaindrasw.club
—

Hash

ValueDescriptionCopy
hash9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b
—
hash1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d
—
hash699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9
—
hash24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7
—
hashdd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4
—

Ip

ValueDescriptionCopy
ip103.160.59.97
CC=IN ASN=AS212667 reconn llc

Threat ID: 6abd5d2f2a4e24523d6a4334

Added to database: 09/30/2026, 19:04:15 UTC

Last enriched: 09/30/2026, 19:20:46 UTC

Last updated: 09/30/2026, 21:53:45 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses