Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Summary

The Russian state-sponsored threat actor known as Star Blizzard has been observed employing a new 'RedFlick' infection chain in recent attacks. This chain is used to deploy the CosmicPulse backdoor through large-scale phishing campaigns.

IFF Assessment

FOE

This article reports on the advanced persistent threat activity of a Russian state-sponsored group using new tools and techniques, which represents a heightened risk to defenders.

Defender Context

Defenders should be aware of the 'RedFlick' infection chain and the CosmicPulse backdoor being used by Star Blizzard. This indicates an evolving TTP (Tactics, Techniques, and Procedures) from a known APT group, potentially targeting a wide range of organizations through phishing.

Read Full Story →