Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Summary
The Russian state-sponsored threat actor known as Star Blizzard has been observed employing a new 'RedFlick' infection chain in recent attacks. This chain is used to deploy the CosmicPulse backdoor through large-scale phishing campaigns.
IFF Assessment
FOE
This article reports on the advanced persistent threat activity of a Russian state-sponsored group using new tools and techniques, which represents a heightened risk to defenders.
Defender Context
Defenders should be aware of the 'RedFlick' infection chain and the CosmicPulse backdoor being used by Star Blizzard. This indicates an evolving TTP (Tactics, Techniques, and Procedures) from a known APT group, potentially targeting a wide range of organizations through phishing.