Threat Intelligence

Russian Hacking Group Star Blizzard Drops ClickFix for New Phishing Trick

Dark Reading · 1 Oct 2026
Key Takeaway Train staff to be cautious of unexpected links or attachments, and keep security tools updated to catch evolving phishing techniques.

Star Blizzard, a Russian state-linked hacking group, has changed its phishing tactics, moving away from its previous ClickFix method to a new approach dubbed RedFlick. The group is using this technique to target Ukrainian-linked organisations, including NGOs, think tanks, and journalists.

The end goal of these attacks is to deploy a backdoor known as CosmicPulse, giving the attackers ongoing access to compromised systems. While the current targets are largely tied to Ukraine-related advocacy and research, the shift in tactics shows that state-backed groups regularly refine their phishing methods to bypass defences and evade detection.

Australian small businesses, particularly those connected to advocacy work, international NGOs, journalism, or policy research, should be aware that phishing techniques used by sophisticated state actors often trickle down or get reused by less skilled attackers over time.

phishing state-sponsored Star Blizzard backdoor Ukraine

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.