Star Blizzard refines phishing and malware delivery with the RedFlick technique
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
Excerpt from the primary source: Microsoft Security Blog & MSRC
Who is affected
Home users · Security professionals
What you should do · Be aware
No immediate action is required, but be alert to related scams or suspicious messages.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Related
ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Hackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens.
More RMM Tools In the Wild, (Tue, Oct 6th)
It seems that a trend started⦠I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[ 1 ] about ScreenConnect used in the wild. Today, I found another one.
Shares in British clothing company ASOS dive after hackers apparently send push notification
Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.
