Star Blizzard Debuts New "RedFlick" Technique to Deliver CosmicPulse Backdoor
BleepingComputer reports that the Russian state-sponsored threat actor Star Blizzard has adopted a new malware installation technique, dubbed "RedFlick," to deploy its known CosmicPulse backdoor. Details on the specific mechanics of RedFlick remain limited in current reporting.
Why It Matters
Star Blizzard (also tracked elsewhere as Callisto Group/COLDRIVER) is a well-documented Russian state actor historically associated with credential-phishing and espionage campaigns targeting government, defense, academic, and NGO personnel. A new delivery technique for an established backdoor like CosmicPulse suggests the group is actively refining its tradecraft to evade existing detections and defenses built around prior delivery methods. Organizations that fall within Star Blizzard's historical targeting — particularly those in government, think tanks, journalism, and defense-adjacent sectors — should treat this as a signal to revisit their exposure to this actor.
What Defenders Should Watch For
- Review existing detections and threat intel tied to Star Blizzard / COLDRIVER and CosmicPulse for currency, since a new installation technique may bypass indicators built around older delivery chains.
- Monitor for anomalous process and script execution patterns consistent with novel loader/dropper behavior, especially following phishing or social-engineering lures, which is this actor's historical initial-access vector.
- Hunt for outbound network connections and persistence mechanisms associated with backdoor installation following any suspicious document or link interaction.
- Ensure endpoint and email security tooling is updated with the latest threat intelligence feeds covering this actor as vendors publish further technical detail.
This is developing, net-new intelligence with limited technical detail publicly available at this time; no specific CVE is associated with this reporting. For full details, see the original report from BleepingComputer.