Star Blizzard evolves phishing and malware techniques with RedFlick
Microsoft detects a new technique by the Russian group Star Blizzard to evade security controls through large-scale phishing campaigns.

Microsoft has observed an evolution in the detection evasion capabilities of the Russian state threat group Star Blizzard. Starting from January 2026, this actor has refined its malicious activities through the creation of large-scale phishing campaigns.
To achieve its goals, the group uses accounts on compromised websites and has introduced a new technique for malware distribution, tracked by Microsoft under the name "RedFlick".
These updates in tactics demonstrate the constant refinement of attack techniques by the Star Blizzard group to overcome security defenses.
