Russian state hackers use new RedFlick technique to push malware

Summary

The Russian state-sponsored hacking group Star Blizzard is employing a novel technique called 'RedFlick' to install their CosmicPulse backdoor. This method involves manipulating Windows services to execute malicious code, allowing the attackers to maintain persistence and conduct further operations.

IFF Assessment

FOE

This article details a new technique used by a state-sponsored threat actor to deploy malware, which represents a new attack vector that defenders must prepare for.

Defender Context

Defenders should be aware of the RedFlick technique, which leverages Windows service manipulation for malware deployment. Monitoring for unusual service behavior and focusing on endpoint detection and response (EDR) capabilities to identify and block such tactics will be crucial.

Read Full Story →