Star Blizzard TTPs observed in 2026 Defending against Star Blizzard and RedFlick-related activity Microsoft Defender detections Hunting queries Indicators of compromise Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”.

Read the full article at Microsoft Security →