Russian state-sponsored cyber group Star Blizzard is using a new infection technique dubbed “RedFlick” in recent attacks to deliver its CosmicPulse backdoor. Multiple outlets report that the change centers on how malware is installed after victims receive phishing lures.

Dark Reading and Bleeping Computer describe “RedFlick” as replacing an earlier approach known as “ClickFix,” enabling Star Blizzard to broaden its phishing reach. The reported targets include Ukrainian-linked organizations such as NGOs, think tanks, and journalists. SecurityWeek similarly reports that Star Blizzard is running larger-scale phishing campaigns aimed at deploying the CosmicPulse backdoor, while using “RedFlick” as part of the infection chain.

While the outlets align on the overall objective—phishing-driven delivery of CosmicPulse using “RedFlick”—they differ slightly in emphasis. SecurityWeek focuses on the scale of the campaigns and the infection chain, whereas Dark Reading and Bleeping Computer highlight the shift away from ClickFix and the specific target types involved.