By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Russian State Hackers Employ RedFlick Technique for Malware Deployment
The Russian state-sponsored hacking group identified as Star Blizzard has been observed employing a novel malware installation technique, which cybersecurity researchers have dubbed "RedFlick." This tactic is specifically used to deploy the group's signature backdoor, known as CosmicPulse. The RedFlick technique leverages a sophisticated method of executing malicious code by exploiting the Windows Registry's "Run" keys, a common feature used by operating systems to launch programs automatically upon startup. However, Star Blizzard's implementation is distinct in its approach to bypassing security measures and ensuring persistent access to compromised systems. The group's primary targets appear to be government entities, indicating a focus on espionage and intelligence gathering.
Star Blizzard, also known by other monikers such as Seaborgium and Cold River, has a documented history of conducting cyber operations aligned with Russian state interests. Their previous activities have included targeting NATO member states and organizations involved in defense and foreign policy. The CosmicPulse backdoor, which RedFlick facilitates the installation of, is a critical component of their toolkit. CosmicPulse is designed to provide attackers with deep access to a victim's system, allowing for the exfiltration of sensitive data, the execution of further commands, and the establishment of a persistent presence. The malware's capabilities include keylogging, capturing screenshots, and downloading and uploading files, making it a versatile tool for cyber espionage.
The RedFlick technique's effectiveness lies in its ability to evade detection by standard antivirus software and intrusion detection systems. By manipulating the Windows Registry in a specific manner, Star Blizzard can ensure that the CosmicPulse malware is executed stealthily during the system's boot process. This method is particularly concerning as it allows the malware to establish a foothold before many security tools have fully initialized or are actively monitoring. The discovery of this new technique highlights the evolving nature of advanced persistent threats (APTs) and the continuous efforts by state-sponsored actors to develop and refine their attack methodologies.
Researchers at Mandiant, a cybersecurity firm that has been tracking Star Blizzard's activities, detailed the RedFlick technique in a recent report. Their analysis indicates that the group has been actively using this method since at least September 2023. The report further elaborates on the technical specifics of RedFlick, including the precise registry keys and values manipulated to achieve code execution. This level of detail is crucial for cybersecurity professionals to develop effective countermeasures and threat intelligence. The ongoing use of such advanced techniques by Star Blizzard underscores the persistent threat posed by Russian state-sponsored cyber operations to national security and critical infrastructure globally. The sophistication of RedFlick suggests a significant investment in research and development by the group to maintain their operational advantage.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.