Malware, Threat Intelligence

Russian hacking group Star Blizzard expands phishing operations with new malware technique

Russia and Presidential elections

Reported by The Record. A Russian state-backed hacking group, known as Star Blizzard, has significantly expanded its phishing operations this year, employing a new technique that simplifies malware infection for victims, according to Microsoft.

Star Blizzard, also tracked as Callisto and ColdRiver and linked to Russia's Federal Security Service, has broadened its attacks beyond Ukraine to target over 100 organizations globally, including NGOs, think tanks, governments, and financial institutions in the U.S. and UK. The group has shifted from highly targeted spear-phishing to mass-mailing campaigns, utilizing compromised websites for phishing messages instead of free email services. Since March, they have used a new malware delivery method called RedFlick, which involves sending a password-protected archive. Upon opening a file within the archive, RedFlick uses scheduled tasks to install the CosmicPulse backdoor, requiring only one user action, unlike previous multi-step methods. Microsoft indicates these changes enhance Star Blizzard's ability to reach more targets, evade detection, and increase successful compromises.

Source: The Record

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds