ProBackend
advanced persistent threats apts
1 hour ago7 min read

Star Blizzard Abandons ClickFix: How This Russian APT's Evolving Toolkit Fits the Broader 2026 AI Cybersecurity Threats Landscape

Star Blizzard (COLDRIVER) is pivoting from ClickFix clipboard attacks to WhatsApp session hijacking and deploying new malware like LOSTKEYS and SPICA. Here's what the shift means for Ukraine-linked networks and AI-era defenses.

A Russian APT Changes Its Playbook — And That Should Worry Everyone

Star Blizzard has been one of the most reliable data points in Russian cyber-espionage since at least 2012. For over a decade, you could predict their moves with uncomfortable accuracy: send a spear-phish, get the target to copy PowerShell from a fake CAPTCHA page, paste it into the Run dialog, done. Credential theft. Inboxes drained. Repeat.

Then Microsoft Threat Intelligence reported something different. The group — also tracked as COLDRIVER, UNC4057, Blue Callisto, Gossamer Bear, and a half-dozen other names depending on which vendor you ask — started targeting WhatsApp accounts. QR code lures tricking diplomats and Ukraine aid workers into linking their mobile messaging sessions to attacker-controlled browsers. No clipboard. No PowerShell prompt. No traditional ClickFix at all.

That's not just a tool swap. It's a signal that this particular threat cluster is adapting to a landscape where ClickFix and clipboard-based delivery have become well-documented enough that defenders catch them. And the implications for the broader AI cybersecurity threats picture in 2026 go well beyond one Russian group's tradecraft choices.

From ClickFix to Session Hijacking: What Actually Happened

For years, the Star Blizzard infection chain was almost embarrassingly simple. A lure website would display a fake CAPTCHA. Once the target clicked "I'm not a robot," the page would silently copy a PowerShell command to their clipboard and instruct them to press Windows+R, paste, and hit Enter. That first-stage PowerShell fetched a second stage — often from 165.227.148[.]68 — which would calculate the MD5 hash of the display resolution and abort if it matched one of three known VM values. Device evasion. Then the real payload would run.

The problem? Everyone started watching for this. CISA flagged the technique. Vendors shipped detection rules. Browser makers built clipboard protections specifically targeting ClickFix attacks. Even APT28, the more aggressive GRU unit, adopted the same social engineering pattern for their own operations, which only accelerated the detection arms race. And the pretext itself went mainstream in the criminal ecosystem too — malicious sponsored-search lures now push booby-trapped custom ChatGPTs using the same fake-CAPTCHA trick.

Star Blizzard's pivot to WhatsApp QR code lures sidesteps all of that. No clipboard to monitor. No PowerShell execution to flag in EDR. Instead, the attacker sends a spear-phishing message, sometimes masquerading as a document or a legitimate invitation, containing a QR code. When a target scans it thinking they're opening a document or joining a video call, they inadvertently link their WhatsApp Web session to the attacker's browser. Full message history. Ongoing access. No script execution required.

LOSTKEYS: A New Data-Theft Malware With Narrow Ambitions

While the WhatsApp pivot grabbed headlines, Google's Threat Intelligence Group quietly documented something arguably more consequential in the COLDRIVER arsenal: a new malware called LOSTKEYS.

LOSTKEYS is a wscript that does exactly one thing well, it steals files. Specifically, it walks through a hard-coded list of file extensions and directories on the victim's machine, collects everything it finds, and exfiltrates the whole package to a hardcoded C2 address. It also runs systeminfo, ipconfig /all, net view, and tasklist, bundling that reconnaissance data with the stolen files.

The delivery chain mirrors what COLDRIVER already knew: fake CAPTCHA → PowerShell to clipboard → second stage → LOSTKEYS. But the targeting tells a different story. GTIG observed LOSTKEYS in January, March, and April 2025 against Western targets and NGOs, not just Ukrainian military networks. This is document theft aimed at people who write policy about Russia, not people who coordinate artillery.

The YARA rule GTIG published uses string replacement patterns, variable naming conventions, and system enumeration commands as detection anchors. If you're running threat hunting infrastructure in 2026, those signatures should be loaded.

SPICA: The Rust Backdoor That's Been Lurking Since 2022

Google TAG also detailed SPICA, a Rust-based backdoor using WebSockets for command and control. Unlike LOSTKEYS, which is a data-collection tool, SPICA provides persistent remote access. It arrives after initial lure documents, encrypted PDFs first observed as early as November 2022, followed by a ZIP file hosted on cloud storage, and finally a payload disguised as "Proton-decrypter.exe."

That naming choice is not accidental. Proton is the encrypted email service used extensively by journalists, NGOs, and diplomats working on Ukraine. Dressing a backdoor as a Proton decryption tool is social engineering with genuine cultural knowledge of the target community.

How This Fits the 2026 AI Cybersecurity Threats Picture

Here's where the Star Blizzard story connects to something bigger than one APT's toolkit choices.

The shift away from ClickFix and toward QR-code session hijacking represents a broader pattern in agentic threat behavior. These are not fully autonomous attacks, COLDRIVER operators still pick targets, craft lures, and manage infrastructure. But the execution layer is increasingly designed to minimize human-machine interaction that traditional security tools were built to detect. AI-powered detection systems that watch for unusual clipboard events, PowerShell execution, or script-based C2 communication get blinded when the attack simply... doesn't do those things anymore.

Securing against this class of threats requires defenses that operate at the identity and session layer rather than the process-execution layer. Session token validation. Messaging platform monitoring. Behavioral analysis of authentication patterns across devices. These are areas where AI-powered security tools genuinely outperform signature-based detection, because the attack signature is the absence of activity you'd expect to see. It's the same defensive posture we've mapped more broadly in securing agentic infrastructure against escalating AI threats.

The broader practice gap is uncomfortable. Most enterprise security stacks in 2026 still alert on the things COLDRIVER used to do, not the things they're doing now.

Who's Actually At Risk

Microsoft's characterization is precise: government and diplomacy personnel (current and former), defense policy researchers whose work touches on Russia, and sources of assistance to Ukraine. That's a specific and fairly small population, but one whose compromise cascades far beyond their own inboxes.

And the perimeter they're being lured through is leaky on multiple fronts — email filtering in particular has been walked past by attackers spoofing internal senders, which is why messaging-channel lures like these are so effective against this population.

Google's guidance for at-risk users centers on the Advanced Protection Program and Enhanced Safe Browsing for Chrome. Neither of those stops a QR code phishing attack on your phone. The real mitigation is policy-level: train these populations that scanning a QR code can be as dangerous as running a PowerShell command.

What Defenders Should Do Now

A few concrete practices for teams facing Russian-linked espionage threats:

Monitor messaging platform authentication events. WhatsApp Web session links, Teams sign-ins from unfamiliar locations, Slack workspace access from new devices, these are the new initial access indicators for targets in diplomacy and defense research.

Update your ClickFix detections to understand they're now a fallback, not the primary vector. The technique still works, APT28 and Star Blizzard both used it in 2024, but state actors are treating it as a commodity tool now that detection coverage is dense.

Load the GTIG YARA rules for LOSTKEYS and SPICA into your hunting platform. These are published, specific, and haven't been widely adopted yet.

Treat QR codes as executable content in your security awareness training. The mental model needs to match the threat: a QR code that opens a URL is no different from a link in a phishing email.

The Bigger Lesson for 2026

Star Blizzard didn't stop being effective. They stopped being predictable. In a landscape where AI cybersecurity threats are increasingly characterized by their ability to exploit the gaps between detection tools, where one product watches the clipboard and another watches network flows but neither watches your phone's camera, a group that simply routes around the entire monitored attack surface has a structural advantage.

The defenses exist. The session-layer monitoring, behavioral authentication analysis, and cross-platform security practices that would catch this are shipping in 2026. The problem is deployment velocity. Nation-state operators iterate on tradecraft faster than enterprises iterate on their tooling. Until that gap closes, expect more pivots like this one.

For related coverage, see AI and autonomous-agent security risks and AI cybersecurity defenses against state-backed espionage.

a russian apt changes its playbook

More blogs