Star Blizzard Uses New RedFlick Malware Delivery Technique to Deploy CosmicPulse Backdoor
Russian state-owned company Star Blizzard is using a new malware delivery technique called RedFlick to deploy its signature CosmicPulse backdoor.
RedFlick is not based on a new cybersecurity technique, but it gives attackers a more automated way to distribute malware while reducing the number of actions required from victims.
Microsoft researchers say Star Blizzard expanded its phishing operations and streamlined its malware distribution process in 2026. The group has been active since 2017 and is known for developing malware families and testing new payload delivery methods, including ClickFix and WhatsApp.
How the RedFlick malware attack works
RedFlick attacks begin with a phishing email, such as an invitation. The attackers then send a second message containing a password-protected ZIP or RAR archive.
The archive contains a VHDX virtual disk with LNK shortcut files disguised as PDF documents. When a victim opens one of the files, it launches a command in a hidden window while displaying a decoy PDF.

Source: Microsoft
The command downloads and runs an MSI installer, which creates three scheduled tasks designed to resemble legitimate Windows maintenance components. Each task serves a different purpose:
- Internet quality test connection: May send the computer or network name and username to the attacker and execute a remote DLL.
- Network configuration manager: Prepares Windows WebDAV functionality to provide access to remote web resources through file-style paths.
- System health monitor: Uses
control.exeto execute the remotely hosted next-stage payload.
Using multiple scheduled tasks with different roles allows the attackers to divide the infection chain into stages and potentially evade detection more effectively.
NOROBOT and BAITSWITCH deliver the CosmicPulse backdoor
The next-stage payload is a downloader known as NOROBOT and BAITSWITCH. It is delivered as a Control Panel Applet file with a .cpl extension and is used to obtain and execute the CosmicPulse backdoor.

Source: Microsoft
BAITSWITCH downloads two ZIP archives. One archive contains a 64-bit Python 3.8 package and a Python file that acts as a bootstrapper for CosmicPulse.
“Bootstrap reads the encryption key from the registry, recovers it using the embedded key in AES-ECB mode, and uses the recovered key to decode the CosmicPulse payload,” Microsoft says.
.jpg)
Source: Microsoft
Microsoft says the backdoor functionality observed in these attacks is consistent with the behavior described in a Google threat intelligence report. This includes executing attacker-supplied Python code to download and execute files or retrieve documents from an infected system.
RedFlick reduces the victim’s role in the infection
From a practical perspective, RedFlick requires a victim to open a malicious shortcut file to trigger an automated infection chain. By comparison, Star Blizzard’s ClickFix attacks required victims to complete multiple manual actions.
Microsoft’s report provides a technical analysis of the RedFlick infection chain and the components used in the attack.
Star Blizzard phishing campaigns target organizations supporting Ukraine
Microsoft says it has observed at least 13 large-scale phishing campaigns affecting more than 100 organizations, primarily in the United States and United Kingdom, since the beginning of the year.
“The Redflick campaign targets Ukrainian individuals and organizations, as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially,” the researchers said.
Despite changing its tactics, techniques, and procedures, Star Blizzard continues to target victims by impersonating trusted contacts and organizations. The group also continues to rely on free email providers to deliver phishing messages.
How organizations can defend against RedFlick attacks
Microsoft recommends that businesses use phishing-resistant authentication, conditional access policies, and email protection. Employees should also independently verify suspicious messages using established contact details rather than replying directly or opening attachments.
Organizations should also consider using an endpoint detection and response (EDR) solution in blocking mode. This can help prevent infections by blocking malicious artifacts, including those that are not detected by antivirus software.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



