Russian state hackers use new RedFlick technique to push malware

by · BleepingComputer

The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed “RedFlick” to deploy its signature CosmicPulse backdoor.

Although the tactic is not a new cybersecurity technique, it is a new delivery approach for the threat actor, allowing it to further automate attacks and reduce victim interaction.

Microsoft researchers say that Star Blizzard expanded its phishing operations and streamlined malware delivery in 2026.

Star Blizzard, active since 2017, is known for exploring new payload delivery avenues like ClickFix or WhatsApp, and for continually developing and deploying new malware families.

New RedFlick technique

RedFlick attacks begin with a phishing email, such as an invitation, followed by a second message containing a password-protected ZIP or RAR archive.

The archive contains a VHDX virtual disk with an LNK file disguised as a PDF. When the file is opened, it launches a command in a hidden window while displaying a decoy PDF to the victim.

VHDX-based attack chain
Source: Microsoft

The commands download and run an MSI installer that creates three scheduled tasks posing as legitimate maintenance components, each with a specific purpose:

  1. Internet Quality Test Connection: sends the computer/network name and username to the attackers and can execute a remote DLL.
  2. Network Configuration Manager: prepares Windows’ WebDAV functionality so remote web resources can be accessed through file-style paths.
  3. System Health Monitor: uses control.exe to execute a remotely hosted next-stage payload.

Since the new method uses multiple scheduled tasks with distinct roles, it helps the attacker evade detection at different stages of the attack.

The next-stage payload is a downloader known as NOROBOT and BAITSWITCH, delivered in the form of a Control Panel applet (.cpl). Its purpose is to fetch and execute the CosmicPulse backdoor.

RedFlick scheduled tasks
Source: Microsoft

BAITSWITCH downloads two ZIP archives, one of them containing the Python 3.8 64-bit package and a Python file acting as a bootstrapper for CosmicPulse.

"The bootstrapper reads the encrypted key from the registry, recovers it using an embedded key in AES-ECB mode, and then uses the recovered key to decode the CosmicPulse payload," Microsoft says.

Attack chain overview
Source: Microsoft

Microsoft notes that the backdoor’s capabilities in the observed attacks remain the same as described in a report from Google in October 2025, including the execution of attacker-supplied Python code to download and run files or retrieve documents from infected systems.

From a practical perspective, RedFlick only requires the victim to open the malicious shortcut file to trigger an automated infection chain, whereas in the ClickFix attacks, Star Blizzard required victims to take multiple manual actions.

Microsoft's report provides technical analysis of the infection chain and the components used in the attacks.

The company says that since the beginning of the year, it has observed at least 13 distinct large-scale phishing campaigns impacting more than 100 organizations, primarily in the United States and the United Kingdom.

“The RedFlick campaigns have targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially,” the researchers say.

Despite changing its tactics, techniques, and procedures, StarBlizzard continues to target users by impersonating trusted contacts or organizations, and still relies on free email providers to deliver phishing messages.

Microsoft recommends that companies use phishing-resistant authentication, Conditional Access policies, email protection, and independently verify suspicious messages through established contact details.

Additionally, using an endpoint detection and response (EDR) solutions in block mode should prevent infections by blocking malicious artifacts even if they are not caught by the antivirus agent.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat