Reported by The Record. A Russian state-backed hacking group, known as Star Blizzard, has significantly expanded its phishing operations this year, employing a new technique that simplifies malware infection for victims, according to Microsoft.
Star Blizzard, also tracked as Callisto and ColdRiver and linked to Russia's Federal Security Service, has broadened its attacks beyond Ukraine to target over 100 organizations globally, including NGOs, think tanks, governments, and financial institutions in the U.S. and UK. The group has shifted from highly targeted spear-phishing to mass-mailing campaigns, utilizing compromised websites for phishing messages instead of free email services. Since March, they have used a new malware delivery method called RedFlick, which involves sending a password-protected archive. Upon opening a file within the archive, RedFlick uses scheduled tasks to install the CosmicPulse backdoor, requiring only one user action, unlike previous multi-step methods. Microsoft indicates these changes enhance Star Blizzard's ability to reach more targets, evade detection, and increase successful compromises.
Source: The Record
