# Star Blizzard (SEABORGIUM)

Published articles for Star Blizzard (SEABORGIUM).

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Star Blizzard refines phishing and malware delivery with the RedFlick technique

DevFeed: [Star Blizzard refines phishing and malware delivery with the RedFlick technique](<https://devfeed.tech/articles/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique-61957.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/>)

Author: Microsoft Threat Intelligence

Published: 2026-09-29T15:00:00Z

Content type: news

Language: en

Sources: [Microsoft Security](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Cloaked Ursa](<https://devfeed.tech/topics/cloaked-ursa.md>), [Aeternum](<https://devfeed.tech/topics/aeternum.md>)

Tags: [blizzard](<https://devfeed.tech/tags/blizzard.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [cyberespionage](<https://devfeed.tech/tags/cyberespionage.md>), [domain-compromise](<https://devfeed.tech/tags/domain-compromise.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [star-blizzard-seaborgium](<https://devfeed.tech/tags/star-blizzard-seaborgium.md>)

### AI overview

Microsoft reports that Star Blizzard has expanded phishing operations and adopted RedFlick, a malware delivery technique that uses scheduled tasks to deploy the CosmicPulse backdoor. The post describes these developments as changes to the group's tactics and provides detection guidance, indicators of compromise, and recommendations for defense.

### Source excerpt

Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as "RedFlick". The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.