Star Blizzard TTPs observed in 2026 Defending against Star Blizzard and RedFlick-related activity Microsoft Defender detections Hunting queries Indicators of compromise Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.
Star Blizzard refines phishing and malware delivery with the RedFlick technique
About this summary. This is a short, independently written summary of an article first published by Microsoft Security. Cyber Security News did not report or verify the underlying story. Read the original: https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/

Source attribution: headline and facts are from Microsoft Security (microsoft.com). Summary method: excerpt of the source description. See our source attribution policy.






