#ParsedReport #CompletenessHigh
30-09-2026
Star Blizzard refines phishing and malware delivery with the RedFlick technique
https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzardhttps://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
Report completeness: High
Actors/Campaigns:
Seaborgium (motivation: cyber_espionage)
Threats:
Redflick_technique
Cosmicpulse
Clickfix_technique
Coldcopy
Spear-phishing_technique
Darksword_tool
Steganography_technique
Norobot
Baitswitch
Yesrobot
Victims:
Ukrainian individuals and institutions, International ngos, Western think tanks, Governments, Financial institutions, Technology sector organizations, Academia, Media, Diplomatic and multilateral organizations, Kyiv hotels, have more...
Industry:
Ngo, Financial, Education, Government
Geo:
Ukraine, Ukrainian, United states, London, United kingdom, Russian
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 6
Domain: 16
IP: 6
Hash: 5
Soft:
Microsoft Defender, Microsoft Defender for Endpoint, Protonmail, CPanel, WordPress, curl
Algorithms:
aes-ecb, base64, aes, zip, sha256
Win Services:
WebClient
Languages:
python, powershell
Platforms:
apple
Post #32921
9