Microsoft Threat Intelligence has disclosed that Star Blizzard — the Russian state-sponsored threat actor linked to the FSB's Center 18 (also tracked as Callisto Group, COLDRIVER, and SEABORGIUM) — has significantly refined its detection evasion tradecraft since January 2026. The campaign combines large-scale social engineering, the operational use of accounts hosted on compromised legitimate websites, and a novel malware delivery technique Microsoft tracks as RedFlick.
This matters to every defender reading this for one reason: Star Blizzard's historical targeting profile is heavily weighted toward government entities, NGOs, think tanks, defense contractors, journalists, and academic institutions — organizations whose users frequently exchange documents with external parties and whose email gateways are routinely trusted by partner organizations. When a state actor moves its staging infrastructure onto compromised legitimate websites, traditional domain-reputation-based filtering loses much of its value overnight. Your blocklist won't save you from a domain that was a legitimate business last week.
This post breaks down the technique from a defender's perspective and provides production-ready Sigma rules, KQL hunt queries, a Velociraptor VQL artifact, and a hardening script you can deploy today.
Who Is Star Blizzard?
Star Blizzard is a long-running Russian intelligence collection operation, widely attributed to FSB Center 18. Its hallmark is patient, highly personalized spear-phishing: reconnaissance of targets via social media and open sources, rapport-building emails, and credential-harvesting infrastructure impersonating legitimate login portals. The group has historically favored credential theft and email exfiltration as its primary objectives, targeting webmail accounts to enable long-term espionage.
What Microsoft is reporting now is an evolution, not a departure: the same social engineering mastery, now paired with delivery infrastructure that deliberately blends into legitimate web traffic.
Technical Analysis: The RedFlick Technique
Based on Microsoft's reporting, the campaign's attack chain exhibits three defining characteristics:
1. Social Engineering at Scale
Star Blizzard continues its established pattern of rapport-building lures — emails crafted to look like they come from known contacts, professional associations, or conference organizers. The lures typically contain links rather than attachments, a deliberate choice that defeats many attachment-focused sandboxing pipelines and pushes the victim interaction into the browser, where endpoint telemetry is often weakest.
2. Compromised Website Accounts as Staging Infrastructure
Rather than registering new malicious domains (which reputation systems flag quickly), the actor is operating from accounts on compromised legitimate websites. The defensive implication is significant:
- The hosting domain has a long, benign history — it passes domain-age and reputation checks.
- TLS certificates are valid and often issued by the legitimate site owner.
- Network defenders see HTTPS traffic to a domain with no prior malicious association.
- Takedown is slower and noisier because the infrastructure is shared with innocent third parties.
This is a classic infrastructure laundering pattern, and it shifts the detection burden decisively from network reputation to endpoint and identity behavior.
3. RedFlick: Novel Malware Delivery
RedFlick is Microsoft's designation for the actor's evolved delivery mechanism. From a defensive standpoint, the key observable behaviors in this class of delivery chain are consistent with the group's historical tradecraft and the evasion goals described:
- User-executed initial access (MITRE ATT&CK T1204): the victim interacts with a lure hosted on the compromised site, frequently through a document, URL file, or redirect chain that ultimately triggers script execution.
- Script interpreter abuse (T1059): PowerShell, Windows Script Host (
wscript.exe/cscript.exe), and HTML Application hosts (mshta.exe) remain the most reliable post-click execution vehicles. Star Blizzard has a documented history of abusingrundll32.exewithurl.dll,FileProtocolHandlerto open attacker-controlled URLs. - Web-based staging (T1105 — Ingress Tool Transfer): payloads and second stages are pulled over HTTPS from the compromised web infrastructure, making the traffic pattern nearly indistinguishable from ordinary browsing at the network layer.
- Evasion refinement: Microsoft's reporting emphasizes detection evasion — expect the actor to avoid writing obvious payloads to disk early in the chain, to favor living-off-the-land binaries, and to gate payloads behind victim validation (checks that the request comes from a real target rather than a sandbox or scanner).
Exploitation status: This is not a software vulnerability — there is no CVE and no patch. This is confirmed, in-the-wild, actively exploited tradecraft by a nation-state actor, observed at scale since January 2026. The remediation is behavioral: detection engineering, hardening, and user-focused controls.
Detection & Response
Because RedFlick's infrastructure is reputation-laundered, your highest-fidelity signals live at the endpoint: what spawned what after a user clicked. The rules below target the behaviors that must occur for this delivery chain to succeed, regardless of which legitimate-looking domain hosts the lure.
Sigma Rules
The following rules are tuned to minimize noise. Rule 1 keys on the mail client / Office → script interpreter pivot, which is the chokepoint for nearly every lure-driven execution chain of this type. Rule 2 targets PowerShell download cradles used for second-stage retrieval. Rule 3 covers the rundll32 url.dll URL-handler abuse long associated with this actor family.
---
title: Mail Client or Office Application Spawning Script Interpreter
id: 3f8c1a72-6b4e-4d91-a2c7-9e5f0d1b8a34
status: experimental
description: Detects Outlook or Office applications spawning script interpreters or LOLBins, consistent with Star Blizzard RedFlick lure-driven execution chains where user interaction with a malicious link or document triggers script execution.
references:
- https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
- https://attack.mitre.org/techniques/T1566/002/
- https://attack.mitre.org/techniques/T1204/
author: Security Arsenal
date: 2026/09/30
tags:
- attack.initial_access
- attack.execution
- attack.t1566.002
- attack.t1204
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\outlook.exe'
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\curl.exe'
- '\certutil.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare; legitimate mail clients and Office apps almost never spawn script interpreters. Investigate every hit.
level: high
---
title: PowerShell Web Download Cradle Execution
id: 8b2e5d41-1c7a-4f63-b9d2-4a6e0c3f7d15
status: experimental
description: Detects PowerShell download-and-execute cradles consistent with second-stage retrieval from compromised web infrastructure, as used in RedFlick-style delivery chains.
references:
- https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
- https://attack.mitre.org/techniques/T1059/001/
- https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/09/30
tags:
- attack.execution
- attack.command_and_control
- attack.t1059.001
- attack.t1105
logsource:
category: process_creation
product: windows
detection:
selection_download:
CommandLine|contains:
- 'DownloadString'
- 'DownloadFile'
- 'Net.WebClient'
- 'Invoke-WebRequest'
- 'Invoke-RestMethod'
- 'Start-BitsTransfer'
selection_exec:
CommandLine|contains:
- 'IEX'
- 'Invoke-Expression'
- '-enc'
- '-ec '
- 'FromBase64String'
condition: selection_download and selection_exec
falsepositives:
- Legitimate administrative scripts that fetch and execute remote content. Baseline your admin tooling; unmanaged endpoints firing this rule warrant immediate triage.
level: high
---
title: Rundll32 URL Protocol Handler Abuse
id: c47a9e06-3d58-4b21-8f4a-2b1d6e9a0c83
status: experimental
description: Detects rundll32.exe invoking url.dll FileProtocolHandler or OpenURL, a technique associated with Star Blizzard for opening attacker-controlled URLs and staging content outside the browser sandbox.
references:
- https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
- https://attack.mitre.org/techniques/T1218/011/
author: Security Arsenal
date: 2026/09/30
tags:
- attack.defense_evasion
- attack.execution
- attack.t1218.011
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\rundll32.exe'
CommandLine|contains:
- 'url.dll,FileProtocolHandler'
- 'url.dll,OpenURL'
- 'ieframe.dll,OpenURL'
condition: selection
falsepositives:
- Very rare in modern environments; some legacy line-of-business applications use these handlers.
level: high
KQL Hunt Query (Microsoft Sentinel / Defender)
This query hunts the lure-driven execution pivot across your fleet: mail clients and browsers spawning script interpreters or LOLBins within a short window — the moment a RedFlick lure converts user interaction into code execution. It also surfaces the follow-on network connection so analysts can see the staged retrieval in one pane.
// Hunt: Star Blizzard RedFlick - mail/browser spawned script execution + network staging
let Lookback = 14d;
let SuspiciousChildren = dynamic(["powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe", "mshta.exe", "rundll32.exe", "curl.exe", "certutil.exe", "bitsadmin.exe"]);
let LureParents = dynamic(["outlook.exe", "winword.exe", "excel.exe", "powerpnt.exe", "msedge.exe", "chrome.exe", "firefox.exe"]);
DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where InitiatingProcessFileName in~ (LureParents)
| where FileName in~ (SuspiciousChildren)
| project Timestamp, DeviceName, AccountName,
ParentProcess = InitiatingProcessFileName,
ChildProcess = FileName, ProcessCommandLine,
ProcessId, DeviceId
| join kind=leftouter (
DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where InitiatingProcessFileName in~ (SuspiciousChildren)
| project DeviceId, InitiatingProcessId, NetTimestamp = Timestamp, RemoteUrl, RemoteIP, RemotePort
) on $left.ProcessId == $right.InitiatingProcessId
| where isnotempty(RemoteUrl) or isnotempty(RemoteIP)
| project Timestamp, DeviceName, AccountName, ParentProcess, ChildProcess, ProcessCommandLine, RemoteUrl, RemoteIP
| order by Timestamp desc
Analyst guidance: Pay particular attention to hits where the RemoteUrl resolves to a domain with legitimate business content but an unusual path depth (e.g., a small business website serving scripts from a user-account subdirectory) — that is the signature of the compromised-website staging Microsoft describes. Also hunt DeviceNetworkEvents for mshta.exe or wscript.exe making outbound HTTPS connections at all; in most mature environments that volume is near zero, and every hit deserves a look.
Velociraptor VQL Hunt Artifact
For DFIR teams validating a suspected compromise, this artifact identifies live processes whose parent chain indicates lure-driven execution, pulling parent process context so you can reconstruct whether the entry point was a mail client or browser session.
-- Hunt: Lure-driven script execution consistent with Star Blizzard RedFlick delivery
-- Flags script interpreters / LOLBins spawned by mail clients, Office, or browsers
LET lure_parents <= ('outlook.exe', 'winword.exe', 'excel.exe', 'powerpnt.exe',
'msedge.exe', 'chrome.exe', 'firefox.exe')
LET suspicious_children <= ('powershell.exe', 'pwsh.exe', 'wscript.exe', 'cscript.exe',
'mshta.exe', 'rundll32.exe', 'curl.exe', 'certutil.exe')
LET procs = SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
SELECT Pid, Ppid, Name AS ProcessName, CommandLine, Username, CreateTime,
parent.Name AS ParentName, parent.Exe AS ParentPath
FROM procs
LET parent = SELECT Name, Exe FROM pslist() WHERE Pid = procs.Ppid
WHERE lowcase(string=Name) IN suspicious_children
AND lowcase(string=ParentName) IN lure_parents
Note for deployment: In Velociraptor's standard VQL you would typically implement the parent lookup as a subquery join rather than the LET parent form above — adapt to your server version. Follow up any hit by collecting the process memory of the script interpreter and pulling the user's browser history and mail-client artifacts for the 24 hours preceding the CreateTime; the lure URL on the compromised site is your best pivot for scoping the campaign across other users.
Remediation & Hardening
There is no patch for RedFlick — the defense is layered hardening plus detection. The following PowerShell script applies the highest-leverage controls on Windows endpoints: Attack Surface Reduction rules that break the lure-to-execution pivot, SmartScreen enforcement, PowerShell logging for post-execution forensics, and Defender cloud-delivered protection.
# Star Blizzard / RedFlick defensive hardening - run elevated, then verify output
# 1. ASR: Block Office applications from creating child processes (kills the lure pivot)
Add-MpPreference -AttackSurfaceReductionRules_Ids "D4F940AB-401B-4EFC-AADC-AD5F3C50688A" -AttackSurfaceReductionRules_Actions Enabled
# 2. ASR: Block execution of potentially obfuscated scripts
Add-MpPreference -AttackSurfaceReductionRules_Ids "5BEB7EFE-FD9A-4556-801D-275E5FFC04CC" -AttackSurfaceReductionRules_Actions Enabled
# 3. ASR: Block JavaScript/VBScript from launching downloaded executable content
Add-MpPreference -AttackSurfaceReductionRules_Ids "D3E037E1-3EB8-44C8-A917-57927947596D" -AttackSurfaceReductionRules_Actions Enabled
# 4. Enable Defender cloud-delivered protection and SmartScreen
Set-MpPreference -MAPSReporting Advanced
Set-MpPreference -SubmitSamplesConsent SendAllSamples
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 1 -Force
# 5. Enable PowerShell Script Block Logging (critical for RedFlick post-execution forensics)
$pslog = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging"
New-Item -Path $pslog -Force | Out-Null
Set-ItemProperty -Path $pslog -Name "EnableScriptBlockLogging" -Value 1
# 6. Verify ASR deployment
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Ids
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Actions
Deploy ASR rules in Audit mode first on a pilot group (replace Enabled with AuditMode), review Microsoft-Windows-Windows Defender/Operational Event IDs 1121/1122, then enforce. The Office child-process rule (D4F940AB) is the single highest-value control against this campaign class and has a well-understood false-positive profile.
Prioritized Remediation Steps
- Identity first — this actor's endgame is credentials. Enforce phishing-resistant MFA (FIDO2/passkeys or certificate-based auth) for all users, prioritizing executives, researchers, and staff in government/NGO/defense verticals. Conditional Access policies should block legacy authentication outright and require compliant devices for mailbox access. Star Blizzard's historical objective is mailbox access; token-theft-resistant authentication removes the prize.
- Deploy the ASR and logging controls from the script above, fleet-wide, starting with high-risk user populations.
- Email security tuning: enable Safe Links / URL rewriting with time-of-click detonation, enable first-contact safety tips, and alert on messages from newly-observed sender domains impersonating known contacts. Because lures ride compromised legitimate sites, pair URL filtering with TLS-agnostic behavioral analysis at click time rather than relying on pre-delivery reputation.
- Import the Sigma rules and run the KQL hunt retroactively over at least 14 days of telemetry. Any hit on Rule 1 or Rule 3 warrants full host triage: pull browser history, mail artifacts, and PowerShell Script Block logs, then scope laterally by the lure URL.
- Threat-hunt outbound traffic from script hosts.
mshta.exe,wscript.exe, andrundll32.exemaking external HTTPS connections should be near-zero events. Baseline and alert. - User awareness targeted at this campaign: brief high-risk staff on Star Blizzard's rapport-building pattern — multi-email conversation threads from apparently known contacts that culminate in a link. The compromised-website twist means "the link looked legitimate" is no longer reassuring; teach users to verify document-sharing requests via a second channel.
- Leverage Microsoft's reporting: review the full Microsoft Security Blog advisory and ingest any published indicators, but treat IOCs as perishable — the actor's use of compromised sites means indicators rotate fast and overlap with legitimate infrastructure. Block at the behavior layer; use IOCs for retro-hunting and scoping.
- If compromise is confirmed: revoke all sessions and refresh tokens for affected identities, force credential resets from a known-clean device, audit mailbox rules and OAuth consents for persistence, and preserve endpoint images before remediation. Engage your IR retainer early — nation-state actors with mailbox access routinely establish redundant persistence.
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.