Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Star Blizzard Deploys ‘RedFlick’ Technique to Boost Phishing and Malware Delivery

Microsoft reports that the Russian state‑sponsored group Star Blizzard has been using a novel RedFlick workflow to combine large‑scale phishing with compromised‑website accounts for malware delivery. The tactic highlights gaps in security‑awareness programs and the need for auditable training evidence.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 microsoft.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
microsoft.com

Star Blizzard Deploys ‘RedFlick’ Technique to Boost Phishing and Malware Delivery

What Happened — Microsoft’s threat‑research team observed the Russian state‑sponsored group Star Blizzard adopting a new “RedFlick” workflow that blends large‑scale phishing lures with compromised‑website accounts to slip malware onto victims’ machines. The technique has been used in campaigns since January 2026 and shows refined evasion against common email‑security controls.

Why It Matters for Trust & Control Assurance

  • RedFlick illustrates how threat actors can bypass static email filters, underscoring the need for continuous, behavior‑based monitoring of inbound communications.
  • The campaign tests an organization’s security‑awareness program; without regular, realistic phishing simulations and training, users remain a high‑risk attack surface.
  • Demonstrates the importance of maintaining auditable evidence of awareness activities and policy enforcement for frameworks such as NIST CSF 2.0.

Who Is Affected – Enterprises across all sectors that rely on email for business communications, especially those with limited security‑awareness programs.

Recommended Actions

  • Refresh your security‑awareness curriculum with recent RedFlick examples and conduct phishing simulations that mimic the technique’s lures.
  • Deploy real‑time email‑gateway analytics that flag anomalous sender domains and compromised‑website account usage.
  • Capture training completion and simulation results as continuous control evidence for audit readiness.

Source: Microsoft Security Blog

Technical Notes – RedFlick leverages compromised accounts on high‑traffic websites to host malicious payloads, then delivers them via spear‑phishing emails that embed short‑lived URLs. The payloads employ obfuscation techniques to evade sandbox detection. No public CVE is associated; the threat is a TTP rather than a software flaw.

Source: same as above

📰 Original Source
https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →