Microsoft says Russian state-sponsored APT Star Blizzard has changed its TTPs to evade detection, shifting from ClickFix to new large-scale phishing and the RedFlick delivery technique. The group has used VHDX containers, malicious LNK files, scheduled tasks, and downloader malware to deploy the CosmicPulse backdoor in campaigns targeting Ukraine-linked organizations and others. #StarBlizzard #RedFlick #CosmicPulse #NoroBot #BaitSwitch #FSB
Keypoints
- Star Blizzard has updated its attack methods to avoid detection.
- The group is sending large-scale phishing emails through compromised websites.
- RedFlick now delivers malware with only one user interaction.
- Attacks have used VHDX files, malicious LNK files, and fake PDF disguises.
- The campaigns deploy NoroBot, BaitSwitch, and the CosmicPulse backdoor.