Russian state hackers use new RedFlick technique to push malware
Summary
The Russian state-sponsored hacking group Star Blizzard is employing a novel technique called 'RedFlick' to install their CosmicPulse backdoor. This method involves manipulating Windows services to execute malicious code, allowing the attackers to maintain persistence and conduct further operations.
IFF Assessment
FOE
This article details a new technique used by a state-sponsored threat actor to deploy malware, which represents a new attack vector that defenders must prepare for.
Defender Context
Defenders should be aware of the RedFlick technique, which leverages Windows service manipulation for malware deployment. Monitoring for unusual service behavior and focusing on endpoint detection and response (EDR) capabilities to identify and block such tactics will be crucial.