Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
First reported by Dark Reading ·
The effectiveness of phishing attacks against journalists and NGOs just got more sophisticated, increasing the risk of data compromise.
Russian state-sponsored hacking group known as Star Blizzard, also identified as APT29 or Nobelium, has shifted its phishing tactics. The group is now employing a new method called "RedFlick" to target entities connected to Ukraine. These targets include non-governmental organizations (NGOs), think tanks, and journalists. The objective of these RedFlick attacks is to deploy a sophisticated backdoor malware known as CosmicPulse. This represents a change from their previous methods, which involved the use of a tool called ClickFix. The adoption of RedFlick aims to expand the group's reach and effectiveness in its cyber operations against Ukrainian-linked organizations.
The shift by Star Blizzard to the "RedFlick" tactic underscores a persistent and evolving threat landscape for organizations involved in sensitive geopolitical research and advocacy. This adaptation suggests that cybercriminals are continually refining their methods to bypass existing security measures and exploit perceived vulnerabilities in less fortified sectors. The use of CosmicPulse, a known backdoor, indicates a focus on persistent access and information exfiltration, rather than solely opportunistic breaches.
This development signals a more concerted effort by state-sponsored actors to penetrate networks associated with critical geopolitical analysis and reporting. It highlights the need for enhanced cybersecurity vigilance and tailored defense strategies within NGOs, think tanks, and journalistic organizations that may not have the same resources as larger corporations. The continued focus on these sectors suggests they are seen as valuable intelligence targets for espionage operations.
AI-written summary. May contain errors.