The Mechanics of the RedFlick Infection Chain
The cybersecurity landscape faces a persistent threat from the Russian state-aligned actor known as Star Blizzard. In 2026, the group introduced a sophisticated delivery tactic identified by Microsoft researchers as RedFlick. This method functions as an automated deployment mechanism for the group’s primary backdoor, CosmicPulse. Unlike previous delivery techniques that demanded significant victim engagement, RedFlick prioritizes automation to streamline the compromise of targeted systems.
The attack initiates via spear-phishing emails, often masquerading as official invitations or routine correspondence. Following the initial contact, the attackers send a secondary communication containing a password-protected ZIP or RAR archive. This archive holds a VHDX virtual disk file, which is a common format for storing virtual hard drives. Inside this VHDX container, victims encounter an LNK file cleverly disguised as a PDF document.
When a user executes this LNK file, the underlying command triggers a silent background process that opens a legitimate-looking decoy PDF to distract the user. Meanwhile, the malicious script initiates a chain of events that bypasses immediate scrutiny. This method reflects a strategic shift for Star Blizzard, moving away from labor-intensive schemes like ClickFix, which required victims to manually execute multiple steps to complete the infection.
Automated Malware Delivery and Execution
Once the initial command runs, the RedFlick technique leverages an MSI installer to establish persistence on the infected system. It achieves this by creating three distinct scheduled tasks that mimic standard Windows maintenance components. These tasks are strategically engineered to fulfill specific roles in the secondary phase of the attack:
The first task, identified as Internet Quality Test Connection, acts as a beacon that transmits the machine and network names to the attacker’s command-and-control server. This phase also creates the capacity for the remote execution of dynamic link libraries (DLLs). The second task, Network Configuration Manager, modifies Windows WebDAV settings to facilitate the retrieval of external resources via file-style paths. Finally, the System Health Monitor task utilizes the Windows control.exe process to trigger a remotely hosted payload.
The deployment of these tasks indicates a high level of operational maturity. By partitioning the infection process into distinct scheduled roles, Star Blizzard complicates the task of security defenders who attempt to correlate these disparate activities. Each stage of the execution chain is designed to be stealthy, minimizing the footprint left behind by the malware at each step.
From Downloader to CosmicPulse Backdoor
The ultimate objective of the RedFlick sequence is the installation of the CosmicPulse backdoor. This process is mediated by intermediate downloaders referred to as NOROBOT and BAITSWITCH. These components arrive in the form of Control Panel applets (CPL files), which, when executed, fetch the necessary assets to finalize the attack.
BAITSWITCH is responsible for downloading two separate ZIP archives. One of these archives contains a localized version of Python 3.8 and a custom bootstrapper script. The bootstrapper is critical to the infection, as it retrieves an encrypted key stored in the Windows registry. It recovers this key using an AES-ECB (Electronic Codebook) mode decryption process. Once the key is recovered, it serves as the master unlocker for the CosmicPulse payload, allowing the backdoor to execute in memory without writing the decrypted executable directly to the disk, which helps evade traditional file-based signature detection.
Once active, CosmicPulse provides the attackers with full control over the compromised system. Its capabilities include the execution of arbitrary Python code, enabling Star Blizzard to download additional malicious tools, exfiltrate sensitive documents, and maintain long-term persistence within high-value environments.
Strategic Impact and Targeted Sectors
Star Blizzard, active since 2017, has focused its efforts on a wide range of organizations, including non-governmental organizations, government bodies, and financial institutions. Since the start of 2026, Microsoft has documented at least 13 large-scale campaigns linked to this group, impacting more than 100 distinct entities, primarily located in the United States and the United Kingdom.
The geopolitical focus of these operations is clear, as the group frequently targets institutions involved in supporting Ukraine. By refining their tactics with RedFlick, the hackers have increased their ability to compromise targets quickly and effectively. Even as the threat actor evolves its technical methodology, its core social engineering tactics remain consistent: they continue to impersonate trusted contacts and utilize free email providers to bypass basic filtering systems.
Defensive Strategies for Organizations
The sophistication of the RedFlick technique highlights the necessity of multi-layered security defenses. Relying solely on signature-based antivirus solutions is no longer sufficient to stop actors that utilize specialized, automated chains.
Microsoft recommends that organizations implement phishing-resistant authentication methods, such as hardware security keys, to mitigate the risk posed by credential harvesting. Furthermore, enforcing Conditional Access policies ensures that sensitive resources cannot be accessed unless specific security conditions are met.
Endpoint Detection and Response (EDR) solutions are particularly critical in this context. When configured in block mode, EDR tools can identify and neutralize suspicious behaviors—such as the creation of atypical scheduled tasks or the unauthorized execution of CPL files—even if the specific malware strain is unknown to the global security community. Finally, organizations must encourage a culture of verification; any unexpected file received, even from a known contact, should be independently verified through a trusted channel before it is opened or executed. By layering these technical controls with improved user awareness, organizations can significantly harden their environments against the evolving methods of state-aligned threat actors.
Disclaimer: This content is auto-generated for informational purposes only.
Source: Read Original News
