Skip to main content
Emerging ThreatsMalware & Ransomware

Star Blizzard Deploys RedFlick Malware via Automated Phishing Attacks

Concerned office worker sits at computer with subtle hint of phishing email on screen.

Since the beginning of the year, Microsoft has observed at least 13 distinct large-scale phishing campaigns impacting more than 100 organizations, primarily in the United States and the United Kingdom, that deploy a new delivery method called "RedFlick" to install the CosmicPulse backdoor, the company reports.

Who is using RedFlick and why it matters

Microsoft attributes the RedFlick delivery approach to the Russian state actor known as Star Blizzard, active since 2017. According to the researchers, Star Blizzard has long experimented with alternate delivery channels — previously using tactics labeled ClickFix and WhatsApp — and continues to iterate on both malware and distribution techniques. In 2026 the group expanded its phishing operations and streamlined malware delivery, trading multi-step user interaction for a largely automated infection chain.

How the RedFlick delivery chain unfolds

RedFlick begins in the familiar vector of phishing mail. Initial messages take the form of invitations or other lures and are followed by a second email containing a password-protected ZIP or RAR archive. That archive hides a VHDX virtual disk which in turn contains an LNK shortcut disguised as a PDF. When a victim opens that shortcut, a command runs in a hidden window while a decoy PDF is shown to the user.

Those commands download and run an MSI installer. The installer creates three scheduled tasks, each masquerading as legitimate maintenance components and each performing a separate role in the intrusion:

  • Internet Quality Test Connection: exfiltrates the computer or network name and username and can execute a remote DLL.
  • Network Configuration Manager: prepares Windows WebDAV functionality so remote web resources can be accessed as file-style paths.
  • System Health Monitor: runs control.exe to execute a remotely hosted next-stage payload.

Microsoft emphasizes that assigning discrete responsibilities to multiple scheduled tasks both automates the chain and helps the actor evade detection at different stages.

The next stage: NOROBOT, BAITSWITCH and CosmicPulse

The attacker’s next-stage downloader is observed under names such as NOROBOT and BAITSWITCH and is delivered as a Control Panel applet (.cpl). That downloader’s job is to fetch and execute the CosmicPulse backdoor. In observed instances BAITSWITCH pulls two ZIP archives, one of which contains the Python 3.8 64-bit distribution and a Python file that serves as a bootstrapper for CosmicPulse.

Per Microsoft’s technical analysis, the bootstrapper reads an encrypted key from the registry, recovers that key using an embedded key with AES in ECB mode, and then uses the recovered key to decode the CosmicPulse payload. Microsoft also notes that the backdoor’s capabilities in these observed attacks match those documented in a Google report from October 2025 — including the ability to execute attacker-supplied Python code to download and run files or to retrieve documents from infected systems.

Targets, scale and the actor’s tradecraft

Microsoft reports that the RedFlick campaigns have targeted “Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially,” the researchers say. The company observed at least 13 large-scale phishing campaigns so far in the year, impacting more than 100 organizations, with the largest footprint concentrated in the United States and the United Kingdom.

Despite changes to delivery and automation, Star Blizzard continues to impersonate trusted contacts or organizations and to rely on free email providers to deliver phishing messages — a reminder that the social-engineering core of these attacks remains unchanged even as the technical packaging evolves.

What this means for security teams, affected organizations, and end users

  • Security teams: Microsoft recommends implementing phishing-resistant authentication, Conditional Access policies, and email protection controls. Additionally, running endpoint detection and response (EDR) solutions in block mode can prevent infections by blocking malicious artifacts even when antivirus signatures miss them.
  • Affected organizations (NGOs, think tanks, governments, financial institutions): these groups are specifically named as targets; organizations supporting Ukraine or working on related issues should independently verify suspicious messages via established contact channels and treat password-protected archives and unexpected attachments as high risk.
  • End users: the red flag for individuals is small and simple — in RedFlick, a single click on a malicious shortcut inside a virtual disk can trigger the automated chain; fewer manual steps are required than in earlier Star Blizzard campaigns, increasing the risk posed by seemingly benign attachments.

Conclusion

RedFlick is not a new class of exploitation technique, but it represents a strategic shift for a persistent state actor: automate delivery, reduce required user interaction, and compartmentalize tasks to complicate detection. Microsoft’s analysis ties a familiar backdoor — CosmicPulse — to a refined chain that mixes social engineering with layered automation, and it documents significant reach across Western countries and Ukraine-related targets. For defenders, the concrete mitigations Microsoft lists — from phishing-resistant authentication to EDR block mode — are practical countermeasures; for investigators, the modularity of the scheduled tasks and the use of a .cpl-based downloader are observable indicators to hunt for in live environments.

Original story