Star Blizzard Refines Phishing And Malware Delivery With The Redflick Technique
Star Blizzard Refines Phishing And Malware Delivery With The Redflick Technique 🚀
Source: Microsoft
Date Published: September 29, 2026
STAR BLIZZARD (also known as APT29 or Nobelium) has significantly evolved its attack methods with its latest campaign, particularly through the innovative RedFlick technique. This advanced persistent threat (APT) actor, recognized for its espionage activities, has refined its initial access and payload delivery techniques, incorporating sophisticated evasion tactics to maintain stealth and persistence.
What is the RedFlick Technique?
The RedFlick technique represents a major leap in STAR BLIZZARD’s operational sophistication, blending social engineering with innovative technical subterfuge. It primarily involves the use of highly customized phishing emails that lure targets into clicking malicious links. RedFlick employs a multi-stage approach where victims are redirected through a series of legitimate-looking, but compromised, websites before reaching a final landing page. This page either prompts for credentials or initiates a malware download, carefully tailored to bypass endpoint detection and response (EDR) systems.
How Does a RedFlick Attack Work?
A typical RedFlick attack begins with a meticulously crafted spear-phishing email. The emails contain a link that, when clicked, initiates a complex redirection chain. The first hop is usually a legitimate, but compromised, website, which acts as a filter, allowing STAR BLIZZARD to check the victim’s IP address, user-agent string, and other environmental factors. If the victim appears to be a security analyst or an automated sandbox, they are redirected to benign content or a non-malicious site. If the initial checks pass, the victim is forwarded to a staging server, often hosted on a cloud platform. The final stage involves the delivery of the primary malware, which can be a custom backdoor, an information stealer, or a remote access Trojan (RAT).
Evasion Techniques
STAR BLIZZARD has integrated several new evasion techniques into RedFlick to minimize detection. These include Geo-fencing and IP filtering, actively blocking IP ranges associated with security vendors and specific geographical locations not targeted. RedFlick extensively uses legitimate system tools (e.g., PowerShell, CertUtil, mshta) for execution, command and control (C2) communication, and data exfiltration, a tactic known as Living off the land binaries (LoLBins). Additionally, all communication between the compromised host and the C2 server is heavily encrypted using custom protocols and frequently rotated domain names.
For more detailed insights, you can read the full article here: Read full article