Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Russian state-sponsored APT Star Blizzard has employed a new malware delivery technique called RedFlick in large-scale phishing campaigns targeting Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions supporting Ukraine. The infection chain involves sending a password-protected archive containing a shortcut file disguised as a PDF, which executes a background script to deliver the CosmicPulse Python backdoor. The group uses scheduled tasks for persistence and has adapted its tactics to evade detection, including multistage execution chains involving PowerShell and MSI installers.
AI Analysis
Technical Summary
Star Blizzard, linked to the Russian FSB Centre 18, has shifted from ClickFix-based delivery to using VHDX files with embedded RedFlick payloads in phishing campaigns observed in 2026. The RedFlick infection chain requires a single user interaction: responding to a phishing email triggers a second email with a password-protected archive containing a malicious shortcut file. This shortcut executes a background script that fetches an MSI installer, sets scheduled tasks for persistence, and launches downloaders (NoroBot or BaitSwitch) to deploy the CosmicPulse backdoor. The group has used scheduled tasks masquerading as legitimate system processes for persistence and has adapted delivery methods to evade defenses. Campaigns have targeted entities supporting Ukraine and have involved mass-mailing phishing platforms and compromised websites.
Potential Impact
The threat actor can gain persistent remote access to targeted systems via the CosmicPulse backdoor, enabling espionage and data exfiltration against high-value targets such as governmental organizations, NGOs, think tanks, and financial institutions. The use of sophisticated delivery and persistence techniques increases the likelihood of successful infection and evasion of detection, posing significant risks to confidentiality and operational security of affected organizations.
Mitigation Recommendations
No vendor advisory or patch information is provided for this threat. Mitigation should focus on user awareness to prevent phishing email interactions, especially responding to suspicious messages and opening password-protected archives. Organizations should monitor for indicators of compromise related to scheduled tasks named 'Internet Quality Test Connection,' 'Network Configuration Manager,' and 'System Health Monitor.' Employing endpoint detection solutions capable of identifying malicious shortcut files, PowerShell execution, and unusual MSI installations can help detect and block this infection chain.
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Description
Russian state-sponsored APT Star Blizzard has employed a new malware delivery technique called RedFlick in large-scale phishing campaigns targeting Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions supporting Ukraine. The infection chain involves sending a password-protected archive containing a shortcut file disguised as a PDF, which executes a background script to deliver the CosmicPulse Python backdoor. The group uses scheduled tasks for persistence and has adapted its tactics to evade detection, including multistage execution chains involving PowerShell and MSI installers.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Star Blizzard, linked to the Russian FSB Centre 18, has shifted from ClickFix-based delivery to using VHDX files with embedded RedFlick payloads in phishing campaigns observed in 2026. The RedFlick infection chain requires a single user interaction: responding to a phishing email triggers a second email with a password-protected archive containing a malicious shortcut file. This shortcut executes a background script that fetches an MSI installer, sets scheduled tasks for persistence, and launches downloaders (NoroBot or BaitSwitch) to deploy the CosmicPulse backdoor. The group has used scheduled tasks masquerading as legitimate system processes for persistence and has adapted delivery methods to evade defenses. Campaigns have targeted entities supporting Ukraine and have involved mass-mailing phishing platforms and compromised websites.
Potential Impact
The threat actor can gain persistent remote access to targeted systems via the CosmicPulse backdoor, enabling espionage and data exfiltration against high-value targets such as governmental organizations, NGOs, think tanks, and financial institutions. The use of sophisticated delivery and persistence techniques increases the likelihood of successful infection and evasion of detection, posing significant risks to confidentiality and operational security of affected organizations.
Defensive Guidance
No vendor advisory or patch information is provided for this threat. Mitigation should focus on user awareness to prevent phishing email interactions, especially responding to suspicious messages and opening password-protected archives. Organizations should monitor for indicators of compromise related to scheduled tasks named 'Internet Quality Test Connection,' 'Network Configuration Manager,' and 'System Health Monitor.' Employing endpoint detection solutions capable of identifying malicious shortcut files, PowerShell execution, and unusual MSI installations can help detect and block this infection chain.
Technical Details
- Classification
- {"confidence":0.55,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/russian-apt-star-blizzard-uses-redflick-infection-chain-in-recent-attacks/","fetched":true,"fetchedAt":"2026-09-30T11:12:15.602Z","wordCount":1102}
Threat ID: 6abcee8f0df196e1a9ed56f3
Added to database: 09/30/2026, 11:12:15 UTC
Last enriched: 09/30/2026, 11:12:22 UTC
Last updated: 09/30/2026, 12:16:26 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.