Russian state hackers use new RedFlick technique to push malware

Russian State Hackers Unleash New Malware Installation Tactic: What You Need to Know

A sophisticated group of Russian state hackers has been using a novel technique called RedFlick to deploy malware on unsuspecting computers. Dubbed Star Blizzard, this threat actor has been making headlines for its innovative approach to cyber attacks, and the latest tactic is no exception.

At its core, RedFlick involves sending victims a phishing email that leads them to download a password-protected archive containing a virtual disk with a malicious shortcut file disguised as a PDF. When opened, the file launches a command in a hidden window while displaying a decoy PDF, making it difficult for victims to detect anything amiss.

But here’s where things get clever: RedFlick uses multiple scheduled tasks to download and run different components of the malware, each with its own specific purpose. One task sends system information to the attackers, another enables remote web access through Windows’ WebDAV functionality, while a third executes a remotely hosted payload. This multi-stage approach makes it harder for security software to detect the attack at various stages.

The final stage of the infection chain involves downloading and executing a downloader known as NOROBOT and BAITSWITCH, which fetches and runs the CosmicPulse backdoor. The backdoor itself has been around since 2025, but its capabilities remain unchanged: it can execute attacker-supplied Python code to download files or retrieve documents from infected systems.

What’s concerning about RedFlick is that it requires minimal interaction from the victim – just opening a malicious shortcut file is enough to trigger an automated infection chain. In contrast, previous attacks by Star Blizzard required victims to take multiple manual actions, making RedFlick a more efficient and effective tactic for the hackers.

Microsoft researchers have observed at least 13 large-scale phishing campaigns using this technique since the beginning of the year, impacting over 100 organizations in the United States, the United Kingdom, and Ukraine. The targets include individuals and institutions that have supported Ukraine politically or financially.

So what can you do to protect yourself? Microsoft recommends using phishing-resistant authentication, Conditional Access policies, email protection, and independently verifying suspicious messages through established contact details. Additionally, implementing endpoint detection and response (EDR) solutions in block mode can prevent infections by blocking malicious artifacts even if they are not caught by antivirus software.

In an era where cyber attacks are becoming increasingly sophisticated, staying one step ahead of the hackers requires a combination of technical expertise, awareness, and proactive measures. By understanding how tactics like RedFlick work and taking steps to mitigate their impact, you can significantly reduce your organization’s risk of falling victim to these types of attacks.


Source: Bleeping Computer — 2026-09-30