Star Blizzard refines phishing and malware delivery with the RedFlick technique
Since January 2026, the Russian state-sponsored threat actor Star Blizzard has enhanced its phishing and malware delivery methods using a novel technique called RedFlick. This evolution includes large-scale phishing campaigns and leveraging compromised website accounts to evade detection. The actor targets Ukrainian individuals and institutions, as well as international NGOs, Western think tanks, governments, and organizations involved in international policy, especially those supporting Ukraine.
AI Analysis
Technical Summary
Microsoft has observed that Star Blizzard, a Russian state threat actor, has refined its operational tradecraft by adopting the RedFlick malware delivery technique alongside large-scale phishing campaigns and the use of compromised website accounts. These tactics improve detection evasion and support ongoing cyberespionage activities. The targeting focuses on Ukrainian entities and international organizations connected to Ukraine support. Indicators include multiple malicious domains, file hashes, and an IP address associated with the campaign. No CVE or specific software vulnerabilities are identified.
Potential Impact
The threat actor's improved phishing and malware delivery capabilities increase the risk of successful cyberespionage against targeted individuals and organizations. This can lead to unauthorized access, data theft, and intelligence gathering, particularly affecting Ukrainian-related entities and international policy organizations. There is no indication of widespread exploitation beyond these targeted campaigns.
Mitigation Recommendations
No official patches or fixes are applicable as this is a threat actor's campaign rather than a software vulnerability. Organizations should apply targeted defenses against phishing and malware, including monitoring for the listed indicators of compromise (domains, hashes, IPs), employing email filtering, and user awareness training focused on phishing threats. Microsoft’s advisory should be consulted for updates. There is no indication that the threat is mitigated or requires no action.
Affected Countries
Ukraine
Indicators of Compromise
- domain: groy.cc
- domain: muvb.net
- domain: bpdaersa.click
- domain: matjk.click
- domain: secure-dns-hub.com
- domain: qumel.link
- domain: ruten.observer
- domain: byveo.org
- domain: guach.net
- domain: stuseamandesilt.org
- hash: 9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b
- hash: 1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d
- hash: 699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9
- hash: 24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7
- hash: dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4
- domain: etia.ca
- domain: gliderrompercycl.com
- domain: divekickspolic.org
- ip: 103.160.59.97
- domain: cyrna.top
- domain: drasw.club
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Description
Since January 2026, the Russian state-sponsored threat actor Star Blizzard has enhanced its phishing and malware delivery methods using a novel technique called RedFlick. This evolution includes large-scale phishing campaigns and leveraging compromised website accounts to evade detection. The actor targets Ukrainian individuals and institutions, as well as international NGOs, Western think tanks, governments, and organizations involved in international policy, especially those supporting Ukraine.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft has observed that Star Blizzard, a Russian state threat actor, has refined its operational tradecraft by adopting the RedFlick malware delivery technique alongside large-scale phishing campaigns and the use of compromised website accounts. These tactics improve detection evasion and support ongoing cyberespionage activities. The targeting focuses on Ukrainian entities and international organizations connected to Ukraine support. Indicators include multiple malicious domains, file hashes, and an IP address associated with the campaign. No CVE or specific software vulnerabilities are identified.
Potential Impact
The threat actor's improved phishing and malware delivery capabilities increase the risk of successful cyberespionage against targeted individuals and organizations. This can lead to unauthorized access, data theft, and intelligence gathering, particularly affecting Ukrainian-related entities and international policy organizations. There is no indication of widespread exploitation beyond these targeted campaigns.
Defensive Guidance
No official patches or fixes are applicable as this is a threat actor's campaign rather than a software vulnerability. Organizations should apply targeted defenses against phishing and malware, including monitoring for the listed indicators of compromise (domains, hashes, IPs), employing email filtering, and user awareness training focused on phishing threats. Microsoft’s advisory should be consulted for updates. There is no indication that the threat is mitigated or requires no action.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/"]
- Adversary
- Star Blizzard
- Pulse Id
- 6abd5b434cf09d69f0ee2e48
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaingroy.cc | — | |
domainmuvb.net | — | |
domainbpdaersa.click | — | |
domainmatjk.click | — | |
domainsecure-dns-hub.com | — | |
domainqumel.link | — | |
domainruten.observer | — | |
domainbyveo.org | — | |
domainguach.net | — | |
domainstuseamandesilt.org | — | |
domainetia.ca | — | |
domaingliderrompercycl.com | — | |
domaindivekickspolic.org | — | |
domaincyrna.top | — | |
domaindrasw.club | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b | — | |
hash1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d | — | |
hash699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9 | — | |
hash24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7 | — | |
hashdd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip103.160.59.97 | CC=IN ASN=AS212667 reconn llc |
Threat ID: 6abd5d2f2a4e24523d6a4334
Added to database: 09/30/2026, 19:04:15 UTC
Last enriched: 09/30/2026, 19:20:46 UTC
Last updated: 09/30/2026, 21:53:45 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.