Russia's Star Blizzard Expands Phishing Operations

The APT group has shifted its strategy, targeting Ukrainian entities with a new phishing method.

3 min readCybersecurity

The Russian APT group known as Star Blizzard has recently altered its approach to cyberattacks, moving away from its previous ClickFix method. This new strategy, referred to as 'RedFlick,' is aimed at Ukrainian organizations, including non-profits, think tanks, and journalists. The group is utilizing this tactic to facilitate the installation of its malicious CosmicPulse backdoor, which allows for unauthorized access to compromised systems. By broadening its phishing efforts, Star Blizzard is enhancing its ability to infiltrate and gather intelligence from these targeted sectors. The shift in tactics underscores the evolving nature of cyber threats, particularly in the context of ongoing geopolitical tensions. As the group refines its methods, it poses a significant risk to the security of organizations linked to Ukraine, highlighting the need for heightened vigilance and robust cybersecurity measures.

Cybersecurity