Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Star Blizzard Uses RedFlick to Deploy CosmicPulse Malware

Microsoft researchers say the Russian state actor Star Blizzard is using a new delivery approach called RedFlick to install its CosmicPulse backdoor. The tactic is not a new cybersecurity technique, but it helps the group automate attacks and reduce the steps required from victims.

RedFlick begins with a phishing email, such as an invitation, followed by a message with a password-protected ZIP or RAR archive. Inside is a VHDX virtual disk containing an LNK shortcut disguised as a PDF. Opening the shortcut runs a command in a hidden window while showing a decoy PDF. The command downloads an MSI installer that creates three scheduled tasks posing as maintenance components.

The tasks help the attackers evade detection at different stages. The next-stage downloader, called NOROBOT and BAITSWITCH, arrives as a Control Panel applet and fetches the CosmicPulse backdoor. Microsoft says BAITSWITCH downloads two ZIP archives; one contains the Python 3.8 64-bit package and a Python bootstrapper that decodes the payload using a recovered encryption key.

Microsoft says CosmicPulse retains capabilities described in a Google report from October 2025, including running attacker-supplied Python code to download files or retrieve documents from infected systems. RedFlick requires victims to open the shortcut, while Star Blizzard's ClickFix attacks required multiple manual actions.

Since the beginning of 2026, Microsoft says it has observed at least 13 large-scale phishing campaigns affecting more than 100 organizations, mainly in the United States and the United Kingdom. Researchers say RedFlick campaigns have targeted Ukrainians and organizations that support Ukraine.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.