Russian APT Group Shifts to New Phishing Technique to Target Ukrainian Organizations

A Russian advanced persistent threat group known as Star Blizzard has abandoned its previous ClickFix phishing method in favor of a new approach called RedFlick to expand attacks against Ukrainian-connected entities including nonprofits, research institutions, and media professionals. The new tactic is being leveraged to distribute CosmicPulse, a backdoor malware designed to establish persistent system access. This shift demonstrates the group's ongoing evolution in attack methodology to evade detection and maintain effectiveness against its preferred targets.
Star Blizzard, classified as an advanced persistent threat group with Russian origins, has modified its operational tactics following detection of its previous ClickFix phishing campaigns. The group now employs RedFlick as its preferred delivery mechanism, broadening its targeting scope to encompass Ukrainian nonprofits, academic research centers, and media professionals. This represents a deliberate strategic adjustment to improve operational effectiveness.
The shift in methodology enables distribution of CosmicPulse, a backdoor tool that grants attackers sustained access to compromised systems. By cycling through new techniques, the threat actor seeks to reduce detection rates and maintain viability against its core target set. Such tactical evolution reflects common patterns among sophisticated threat groups adapting to defensive measures.
The targeting of Ukrainian institutional and media sectors could disrupt critical information flows, research continuity, and civil society operations during ongoing geopolitical tensions. Organizations in these sectors may face heightened operational risks requiring enhanced security posture. The campaign illustrates how persistent threat groups continuously adapt methods to penetrate defended networks, potentially affecting organizational security planning and resource allocation across affected regions and sectors.