Russian State Hackers Leverage RedFlick Technique to Deliver Malware
A new wave of sophisticated cyber attacks has been unleashed by the Russian state actor Star Blizzard, exploiting a technique dubbed “RedFlick” to deploy its signature CosmicPulse backdoor. This latest tactic marks a significant evolution in the threat actor’s arsenal, enabling them to automate attacks and reduce victim interaction.
Star Blizzard, active since 2017, is notorious for pushing the boundaries of payload delivery, often employing unconventional methods such as using WhatsApp or ClickFix. The group has consistently demonstrated its ability to adapt and innovate, continually developing new malware families and refining its tactics.
The RedFlick technique involves a phishing email, typically masquerading as an invitation, followed by a second message containing a password-protected ZIP or RAR archive. Within this archive lies a VHDX virtual disk with an LNK file disguised as a PDF. When the file is opened, it launches a command in a hidden window while displaying a decoy PDF to the victim.
The commands then download and run an MSI installer that creates three scheduled tasks, each posing as legitimate maintenance components. These tasks are designed to perform distinct functions: Internet Quality Test Connection sends computer/network information to the attackers; Network Configuration Manager prepares Windows’ WebDAV functionality for remote resource access; and System Health Monitor executes a remotely hosted next-stage payload.
The RedFlick method’s use of multiple scheduled tasks with distinct roles allows the attacker to evade detection at various stages of the attack. The next-stage payload, NOROBOT and BAITSWITCH, is delivered in the form of a Control Panel applet (.cpl), which fetches and executes the CosmicPulse backdoor.
According to Microsoft researchers, the bootstrapper for CosmicPulse reads an encrypted key from the registry, recovers it using an embedded key in AES-ECB mode, and then uses the recovered key to decode the payload. The backdoor’s capabilities remain unchanged from a report by Google in October 2025, including the execution of attacker-supplied Python code.
From a practical perspective, RedFlick only requires the victim to open the malicious shortcut file to trigger an automated infection chain, whereas in ClickFix attacks, Star Blizzard required victims to take multiple manual actions. Microsoft’s report provides technical analysis of the infection chain and components used in the attacks.
The company notes that it has observed at least 13 distinct large-scale phishing campaigns impacting over 100 organizations since the beginning of the year, primarily targeting users in the United States and the United Kingdom. The RedFlick campaigns have also targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions supporting Ukraine.
To mitigate these attacks, Microsoft recommends that companies employ phishing-resistant authentication, Conditional Access policies, email protection, and verify suspicious messages through established contact details. Additionally, using an endpoint detection and response (EDR) solution in block mode can prevent infections by blocking malicious artifacts even if they are not caught by the antivirus agent.
As cyber threats continue to evolve at breakneck speed, it is essential for organizations to stay vigilant and adapt their security strategies accordingly.
Source: Bleeping Computer — 2026-09-30