Russian state hackers use new RedFlick technique to push malware
The Russian state-sponsored threat actor Star Blizzard has developed a new malware delivery technique called RedFlick to deploy its CosmicPulse backdoor. This method automates the infection chain by using a password-protected archive containing a virtual disk with a malicious shortcut file, which when opened, triggers hidden commands to download and install malware components via scheduled tasks. These tasks perform distinct roles to evade detection and ultimately deliver the CosmicPulse backdoor, capable of executing attacker-supplied Python code. The campaigns primarily target Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial organizations supporting Ukraine. Microsoft recommends phishing-resistant authentication, Conditional Access policies, email protection, and endpoint detection and response solutions to mitigate these attacks.
AI Analysis
Technical Summary
Star Blizzard, active since 2017, has introduced the RedFlick technique in 2026 to automate malware deployment of its CosmicPulse backdoor. The attack starts with phishing emails containing password-protected ZIP or RAR archives that hold a VHDX virtual disk with an LNK file disguised as a PDF. Opening the LNK file runs hidden commands that download an MSI installer creating three scheduled tasks with specific functions: sending system info, enabling WebDAV for remote access, and executing a remote payload. The next-stage payload downloader (NOROBOT and BAITSWITCH) fetches the CosmicPulse backdoor, which decrypts its payload using keys stored in the registry and executes attacker-supplied Python code. This method reduces victim interaction compared to previous tactics and has been observed in at least 13 large-scale phishing campaigns affecting over 100 organizations, mainly in the US and UK, with targets linked to Ukraine support. Microsoft provides detailed technical analysis and mitigation recommendations.
Potential Impact
The RedFlick technique enables Star Blizzard to automate malware installation with minimal victim interaction, increasing infection efficiency. The CosmicPulse backdoor allows execution of arbitrary Python code supplied by attackers, enabling file downloads, execution, and document theft from infected systems. The use of multiple scheduled tasks with distinct roles helps evade detection at various stages. The campaigns have targeted politically sensitive organizations and individuals, potentially leading to espionage, data theft, and disruption.
Mitigation Recommendations
Microsoft recommends implementing phishing-resistant authentication methods, enforcing Conditional Access policies, and deploying robust email protection to reduce phishing risks. Organizations should independently verify suspicious messages through established contact channels. Using endpoint detection and response (EDR) solutions in block mode can prevent infections by blocking malicious artifacts even if antivirus solutions do not detect them. No official patch is applicable as this is a threat actor technique rather than a software vulnerability.
Russian state hackers use new RedFlick technique to push malware
Description
The Russian state-sponsored threat actor Star Blizzard has developed a new malware delivery technique called RedFlick to deploy its CosmicPulse backdoor. This method automates the infection chain by using a password-protected archive containing a virtual disk with a malicious shortcut file, which when opened, triggers hidden commands to download and install malware components via scheduled tasks. These tasks perform distinct roles to evade detection and ultimately deliver the CosmicPulse backdoor, capable of executing attacker-supplied Python code. The campaigns primarily target Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial organizations supporting Ukraine. Microsoft recommends phishing-resistant authentication, Conditional Access policies, email protection, and endpoint detection and response solutions to mitigate these attacks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Star Blizzard, active since 2017, has introduced the RedFlick technique in 2026 to automate malware deployment of its CosmicPulse backdoor. The attack starts with phishing emails containing password-protected ZIP or RAR archives that hold a VHDX virtual disk with an LNK file disguised as a PDF. Opening the LNK file runs hidden commands that download an MSI installer creating three scheduled tasks with specific functions: sending system info, enabling WebDAV for remote access, and executing a remote payload. The next-stage payload downloader (NOROBOT and BAITSWITCH) fetches the CosmicPulse backdoor, which decrypts its payload using keys stored in the registry and executes attacker-supplied Python code. This method reduces victim interaction compared to previous tactics and has been observed in at least 13 large-scale phishing campaigns affecting over 100 organizations, mainly in the US and UK, with targets linked to Ukraine support. Microsoft provides detailed technical analysis and mitigation recommendations.
Potential Impact
The RedFlick technique enables Star Blizzard to automate malware installation with minimal victim interaction, increasing infection efficiency. The CosmicPulse backdoor allows execution of arbitrary Python code supplied by attackers, enabling file downloads, execution, and document theft from infected systems. The use of multiple scheduled tasks with distinct roles helps evade detection at various stages. The campaigns have targeted politically sensitive organizations and individuals, potentially leading to espionage, data theft, and disruption.
Defensive Guidance
Microsoft recommends implementing phishing-resistant authentication methods, enforcing Conditional Access policies, and deploying robust email protection to reduce phishing risks. Organizations should independently verify suspicious messages through established contact channels. Using endpoint detection and response (EDR) solutions in block mode can prevent infections by blocking malicious artifacts even if antivirus solutions do not detect them. No official patch is applicable as this is a threat actor technique rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.85,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6abd75882a4e24523d92d2d2
Added to database: 09/30/2026, 20:48:08 UTC
Last enriched: 09/30/2026, 20:48:15 UTC
Last updated: 09/30/2026, 21:48:45 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.