Star Blizzard refines phishing and malware delivery with the RedFlick technique

    Date: 09/30/2026

    Severity: High

    Summary

    Researchers report that Russian Star Blizzard (SEABORGIUM) has expanded its phishing operations in 2026, using large-scale phishing campaigns, compromised websites, and social engineering to target organizations, particularly those connected to Ukraine. The group introduced RedFlick, a malware-delivery technique that uses multiple scheduled tasks to deploy the CosmicPulse backdoor, reducing the infection chain to a single user interaction. The campaigns also employ VHDX lures, malicious MSI files, credential theft, persistence, and detection evasion, with activity observed across more than 100 organizations. 

    Indicators of Compromise (IOC) List

    Domain/URLs

    bpdaersa.click

    byveo.org

    cyrna.top

    divekickspolic.org

    drasw.club

    etia.ca

    gliderrompercycl.com

    groy.cc

    guach.net

    itechx.tel

    matjk.click

    muvb.net

    qumel.link

    ruten.observer

    secure-dns-hub.com

    stuseamandesilt.org

    IP Address

    103.160.59.97

    103.245.231.248

    103.245.231.79

    2.57.241.246

    45.84.59.66

    89.125.209.168

    Hash

    1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d

    24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7

    699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9

    9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b

    dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "drasw.club" or url like "drasw.club" or siteurl like "drasw.club" or domainname like "bpdaersa.click" or url like "bpdaersa.click" or siteurl like "bpdaersa.click" or domainname like "gliderrompercycl.com" or url like "gliderrompercycl.com" or siteurl like "gliderrompercycl.com" or domainname like "qumel.link" or url like "qumel.link" or siteurl like "qumel.link" or domainname like "itechx.tel" or url like "itechx.tel" or siteurl like "itechx.tel" or domainname like "guach.net" or url like "guach.net" or siteurl like "guach.net" or domainname like "groy.cc" or url like "groy.cc" or siteurl like "groy.cc" or domainname like "etia.ca" or url like "etia.ca" or siteurl like "etia.ca" or domainname like "secure-dns-hub.com" or url like "secure-dns-hub.com" or siteurl like "secure-dns-hub.com" or domainname like "matjk.click" or url like "matjk.click" or siteurl like "matjk.click" or domainname like "divekickspolic.org" or url like "divekickspolic.org" or siteurl like "divekickspolic.org" or domainname like "stuseamandesilt.org" or url like "stuseamandesilt.org" or siteurl like "stuseamandesilt.org" or domainname like "muvb.net" or url like "muvb.net" or siteurl like "muvb.net" or domainname like "byveo.org" or url like "byveo.org" or siteurl like "byveo.org" or domainname like "cyrna.top" or url like "cyrna.top" or siteurl like "cyrna.top"

    Detection Query 2 :

    dstipaddress IN ("103.245.231.79","103.245.231.248","45.84.59.66","89.125.209.168","103.160.59.97","2.57.241.246") or srcipaddress IN ("103.245.231.79","103.245.231.248","45.84.59.66","89.125.209.168","103.160.59.97","2.57.241.246")

    Detection Query 3 :

    sha256hash IN ("699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9","dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4","24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7","9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b","1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d")

    Reference:

    https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/


    Tags

    MalwareThreat ActorStar BlizzardSocial EngineeringPhishingRedFlickUkraineCredential HarvestingBackdoorRussia

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags