Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

Many snowflakes falling against trees with bare branches
Source: Ulrick T via Alamy Stock Photo

A Russia-linked advanced persistent threat (APT) actor that was significantly disrupted by Microsoft and US officials two years ago is casting a wider net than ever with its phishing and malware-delivery tactics. In recent attacks, the nation-state actor has ditched its previous ClickFix strategy for a novel technique, allowing it to reach even more targets and evade detection.

Star Blizzard, active since 2017 and known for targeting journalists, nongovernmental organizations (NGOs), and Russia experts — particularly those supporting Ukraine — has since January demonstrated a key tactical change in its phishing initial-access method, Microsoft Threat Intelligence (MTI) revealed in a blog post on Sept. 29.

"As part of this evolution, Star Blizzard adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse," according to MTI's post.

Related:'NeedyMantis' Provides Long-Term Access to Compromised Networks

The technique signals a departure from the actor's previous use of the social engineering tactic ClickFix, which required several actions by the victim before deploying CosmicPulse, a Python-based backdoor, Microsoft said. "By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process," according to the post.

This change, combined with the actor's shift toward large-scale phishing operations during the same period, likely increases the APT's chance of success, Microsoft warned, which should put organizations typically in Star Blizzard's crosshairs on alert.

Latest Star Blizzard Activity

Star Blizzard, also referred to as ColdRiver and Callisto, is a subordinate to the Russian Federal Security Service Center (FSB) Center 18, according to the US Cybersecurity and Infrastructure Security Agency (CISA). In the past, the actor primarily used phishing emails to steal login credentials from its victims and was the target of a 2024 joint operation by Microsoft and the Department of Justice to seize 41 of Star Blizzard's Internet domains.

Undaunted, Star Blizzard has continued to evolve, with Microsoft detecting 13 distinct "large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide" since January. Though early campaigns targeted users of the Ukrainian email provider Ukr.net by impersonating Ukrainian tax or other authorities, campaigns starting in March expanded beyond Ukraine.

Indeed, Star Blizzard has significantly widened the scale of its email attacks, sending hundreds of messages per campaign in contrast to its previous, carefully researched and narrowly focused spear-phishing operations. The lures remain similar to previous campaigns, impersonating tax authorities, financial organizations, and prominent think tanks, or sending fake invitations to closed-door security, diplomatic, economic, and geopolitical events, Microsoft said.

Related:UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

"Microsoft also observed the actor target multiple individuals within the same organization, with phishing emails often crafted to appear as internal communications originating from the targeted organization itself," according to the post.

Furthermore, in new campaigns, Star Blizzard is showing off new capabilities previously unassociated with the actor, including steganography to conceal identifiers and the targeting of vulnerable Apple iOS devices to deploy the DarkSword backdoor, as reported by Proofpoint in March.

Various RedFlick Infection Paths

RedFlick signals a major change to how Star Blizzard is targeting victims through email, Microsoft said. RedFlick is a malware delivery and persistence technique with various infection paths that all share a common thread: an effort to make malicious execution blend into normal Windows activity while reducing the amount of work required from the victim.

Related:Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

In campaigns observed by Microsoft, victims receive password-protected zip or RAR archives containing an LNK file disguised as a document, often a PDF. The LNK uses Windows utilities such as conhost.exe and cmd.exe to start the infection chain via an MSI installer that creates scheduled tasks to execute malware, reducing the manual steps required compared with the actor's earlier ClickFix campaigns.

Star Blizzard in July demonstrated another infection chain that required little more than the victim opening a lure and used trusted Windows components to handle execution, persistence, and payload retrieval, according to Microsoft. This chain hid PowerShell payload data inside an apparently legitimate PDF, which eventually created scheduled tasks and ultimately launched the CPL-based CosmicPulse downloader with minimal user interaction.

Piyush Sharma, co-founder and CEO of security firm Tuskira, says the speed with which Star Blizzard is reducing its interaction with victims on its way to compromising them is notable, demonstrating rapid evolution and determination in the actor's latest phishing attacks.

"What interests me about RedFlick is how much work it takes away from the victim," he says, adding that he is particularly impressed by the PowerShell technique that surfaced in July to hide part of the delivery chain inside a PDF.

"That’s a lot of adjustment in a few months, with the same backdoor still at the end of it," Sharma observes.

Defending Against Changing Star Blizzard Tactics

Though Star Blizzard has changed its tactics, its overall phishing patterns remain the same, and Microsoft advised organizations to set their security defenses accordingly. Recommended mitigations include using phishing-resistant authentication methods; locking down account access using conditional access policies; and using advanced anti-phishing solutions that monitor and scan incoming emails and visited websites.

Organizations also should continue with other general security mitigations to reduce the impact of a successful initial entry via Star Blizzard's attack chain, including using endpoint detection and response (EDR) in block mode to block malicious artifacts.

Microsoft also encouraged organizations to use Web browsers that support Microsoft Defender SmartScreen, which identifies and blocks malicious websites, including phishing sites, scam sites, and sites that host malware.

Tuskira's Sharma warns that other threat groups may attempt to copy Star Blizzards' RedFlick techniques going forward. Thus, he advises defenders to test whether their security controls "catch the chain after the click, from the scheduled tasks through to the backdoor," and then repeat those tests as the packaging of the infection chain changes.

进一步分析

免费工具,针对本文主题进一步深挖分析:

source: DarkReading