Russia's Star Blizzard hacking group has shifted away from ClickFix phishing campaigns to deploy a new attack method called RedFlick against Ukrainian-aligned targets. The group now targets nongovernmental organizations, think tanks, and journalists with the goal of installing its CosmicPulse backdoor.

Star Blizzard, a Russian state-sponsored APT group tracked by Recorded Future, has been active since at least 2014. The group historically used ClickFix, a social engineering technique that tricks users into clicking malicious links by displaying fake browser error messages. That method proved effective but attracted security attention.

The shift to RedFlick marks a tactical evolution. Unlike ClickFix, which relies on browser pop-ups and fake system alerts, RedFlick uses a different delivery mechanism tailored to penetrate Ukrainian organizations. The exact technical details of RedFlick remain under investigation by security researchers, but the rebranding signals Star Blizzard's effort to evade detection patterns that defenses now recognize.

The targets reveal the operation's strategic focus. NGOs, think tanks, and journalist organizations represent valuable intelligence sources for Russian state interests. These entities often work on Ukraine-related policy, human rights documentation, and conflict analysis. Compromising them gives Moscow insight into Western perspectives on Ukraine, NATO positioning, and sanctions strategy.

CosmicPulse, the backdoor deployed through RedFlick, grants Star Blizzard persistent remote access. Once installed, the malware enables command execution, data exfiltration, and lateral movement within networks. For organizations without robust endpoint detection capabilities, CosmicPulse can operate silently for extended periods.

The timing of this tactical shift aligns with intensified Russian intelligence operations targeting Ukraine and its supporters. Star Blizzard has conducted similar campaigns against U.S. government agencies, European officials, and defense contractors. The group operates with the direct support of Russia's FSB security service, making it one of Moscow's most capable cyber espionage units.

Organizations in Ukraine and those supporting Ukrainian causes face elevated risk. Security teams should implement endpoint detection and response tools capable of identifying CosmicPulse's behavioral signatures. Email filtering should flag suspicious links and attachments, particularly those claiming system errors or urgent updates. Multi-factor authentication reduces the impact of compromised credentials.

RedFlick's emergence demonstrates that threat actors continuously refine their techniques when existing methods face detection. This pattern repeats across Russian, Chinese, North Korean, and Iranian APT groups. Defenders who rely solely on blocking known ClickFix indicators will miss RedFlick campaigns.

Ukrainian and Western organizations working on policy, analysis, or human rights documentation should treat this campaign as a direct threat. Journalists and analysts face personal risk from account compromise. NGO networks, often less mature than corporate environments, may lack the detection tools needed to spot CosmicPulse infections.

Recorded Future and other threat intelligence vendors continue monitoring Star Blizzard's infrastructure and command-and-control servers. The group's operational patterns suggest RedFlick will remain active as long as it succeeds. Once defensive detection improves, Star Blizzard will likely deploy yet another variant, maintaining the cycle of espionage.