RedFlick technique lets Star Blizzard push CosmicPulse

RedFlick technique lets Star Blizzard push CosmicPulse

Star Blizzard, a Russian state-backed threat actor, has adopted a new way of installing malware on victims' machines. Microsoft researchers call the method "RedFlick" and say the group is using it to deliver its signature CosmicPulse backdoor.

The technique itself is not new to the security world. What is new is that Star Blizzard now uses it. It lets the group automate more of each attack and cut down on what the victim has to do before the infection runs.

According to Microsoft, Star Blizzard expanded its phishing operations in 2026 and made its malware delivery more efficient. The group has been active since 2017. It has a history of trying out new ways to deliver payloads, including ClickFix and WhatsApp, and it keeps building and deploying new malware families.

From a phishing email to a fake PDF

A RedFlick attack starts with a phishing email, such as an invitation. A second message follows with a password-protected ZIP or RAR archive attached.

Inside the archive is a VHDX virtual disk. That disk holds an LNK shortcut file made to look like a PDF. When the victim opens it, a command runs in a hidden window while a decoy PDF is shown on screen.

The hidden command downloads and runs an MSI installer. The installer sets up three scheduled tasks that pose as legitimate maintenance components. Each one has its own job:

  • Internet Quality Test Connection sends the computer or network name and the username to the attackers, and can run a remote DLL.
  • Network Configuration Manager prepares the Windows WebDAV feature so remote web resources can be reached through file-style paths.
  • System Health Monitor uses control.exe to run a next-stage payload hosted remotely.

Splitting the work across several scheduled tasks with separate roles helps the attackers avoid detection at different points in the chain.

BAITSWITCH and the CosmicPulse backdoor

The next-stage payload is a downloader tracked as NOROBOT and BAITSWITCH. It arrives as a Control Panel applet (.cpl file), and its purpose is to fetch and run CosmicPulse.

BAITSWITCH pulls down two ZIP archives. One of them contains the 64-bit Python 3.8 package and a Python file that acts as a bootstrapper for CosmicPulse.

"The bootstrapper reads the encrypted key from the registry, recovers it using an embedded key in AES-ECB mode, and then uses the recovered key to decode the CosmicPulse payload," Microsoft explained.

The backdoor's capabilities in these attacks have not changed from those Google described in a report in October 2025. They include running Python code supplied by the attackers to download and execute files or to take documents from infected systems.

In practice, the main difference is how little the victim has to do. With RedFlick, opening the malicious shortcut is enough to start an automated infection chain. In earlier ClickFix attacks, Star Blizzard needed victims to complete several manual steps.

More than 100 organizations hit

Microsoft says it has seen at least 13 distinct large-scale phishing campaigns since the start of the year. These hit more than 100 organizations, mostly in the United States and the United Kingdom.

"The RedFlick campaigns have targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially," the researchers said.

Some things have not changed. Star Blizzard still impersonates trusted contacts or organizations, and it still sends its phishing messages through free email providers.

Microsoft advises organizations to use phishing-resistant authentication, Conditional Access policies and email protection. Suspicious messages should be checked independently through contact details that are already known. The company also recommends running endpoint detection and response (EDR) tools in block mode, which should stop infections by blocking malicious artifacts even when the antivirus agent misses them.

Our Take

RedFlick fits a pattern we have followed for some time. Star Blizzard has been scaling up phishing against Ukraine's backers, and this report shows the group is working on the delivery side as well as on volume. The move away from ClickFix is worth noting. That lure has spread widely among criminals, with recent cases such as a malicious Custom GPT pushing a RAT. Because it needs several manual steps from the victim, every extra step is another chance for the victim to stop. A single click on a fake PDF lowers that barrier.

For defenders, the details give useful hunting points: VHDX files inside password-protected archives, LNK files posing as documents, new scheduled tasks with generic maintenance names, and control.exe loading remote content. Many organizations may be able to block or flag mounted virtual disk files from email altogether.

The target list matters too. NGOs, think tanks and financial institutions that support Ukraine often have smaller security teams than government agencies. Together with Russian mobile malware aimed at iOS and Android users, this suggests the pressure on that wider support network is not easing. It is worth watching whether CosmicPulse itself gets new features next, since so far only its delivery has changed.