Skip to main content

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

0
High
Malwarephishing
Published: 09/30/2026 (09/30/2026, 10:59:30 UTC)
Source: SecurityWeek

Description

Russian state-sponsored APT Star Blizzard has employed a new malware delivery technique called RedFlick in large-scale phishing campaigns targeting Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions supporting Ukraine. The infection chain involves sending a password-protected archive containing a shortcut file disguised as a PDF, which executes a background script to deliver the CosmicPulse Python backdoor. The group uses scheduled tasks for persistence and has adapted its tactics to evade detection, including multistage execution chains involving PowerShell and MSI installers.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 11:12:22 UTC

Technical Analysis

Star Blizzard, linked to the Russian FSB Centre 18, has shifted from ClickFix-based delivery to using VHDX files with embedded RedFlick payloads in phishing campaigns observed in 2026. The RedFlick infection chain requires a single user interaction: responding to a phishing email triggers a second email with a password-protected archive containing a malicious shortcut file. This shortcut executes a background script that fetches an MSI installer, sets scheduled tasks for persistence, and launches downloaders (NoroBot or BaitSwitch) to deploy the CosmicPulse backdoor. The group has used scheduled tasks masquerading as legitimate system processes for persistence and has adapted delivery methods to evade defenses. Campaigns have targeted entities supporting Ukraine and have involved mass-mailing phishing platforms and compromised websites.

Potential Impact

The threat actor can gain persistent remote access to targeted systems via the CosmicPulse backdoor, enabling espionage and data exfiltration against high-value targets such as governmental organizations, NGOs, think tanks, and financial institutions. The use of sophisticated delivery and persistence techniques increases the likelihood of successful infection and evasion of detection, posing significant risks to confidentiality and operational security of affected organizations.

Defensive Guidance

No vendor advisory or patch information is provided for this threat. Mitigation should focus on user awareness to prevent phishing email interactions, especially responding to suspicious messages and opening password-protected archives. Organizations should monitor for indicators of compromise related to scheduled tasks named 'Internet Quality Test Connection,' 'Network Configuration Manager,' and 'System Health Monitor.' Employing endpoint detection solutions capable of identifying malicious shortcut files, PowerShell execution, and unusual MSI installations can help detect and block this infection chain.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.55,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/russian-apt-star-blizzard-uses-redflick-infection-chain-in-recent-attacks/","fetched":true,"fetchedAt":"2026-09-30T11:12:15.602Z","wordCount":1102}

Threat ID: 6abcee8f0df196e1a9ed56f3

Added to database: 09/30/2026, 11:12:15 UTC

Last enriched: 09/30/2026, 11:12:22 UTC

Last updated: 09/30/2026, 12:16:26 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses