ThreatPaper
Assessed, Not Confirmed

Star Blizzard has ditched ClickFix for RedFlick

Assessment

Dark Reading's headline states Star Blizzard 'ditches ClickFix.' Microsoft calls RedFlick 'a notable departure from the actor's previous use of ClickFix-based infection chains' for delivering CosmicPulse, so RedFlick does supersede ClickFix (Google's COLDCOPY) as the primary malware-delivery chain. But Microsoft also says it 'continues to observe some previously reported Star Blizzard phishing techniques throughout 2026,' including Evilginx credential phishing, so the actor has not abandoned all prior tradecraft. The framing is defensible for malware delivery but overstates a wholesale abandonment.

Where this claim appeared

Dark Reading · 2026-09-30

https://www.darkreading.com/threat-intelligence/russia-star-blizzard-apt-ditches-clickfix-widen-phishing-net

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Star Blizzard's RedFlick technique delivers the CosmicPulse backdoor to 100+ organizations

Think this assessment is wrong? Report an error.