Back to Feed
Nation-stateSep 30, 2026

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Russian APT Star Blizzard uses RedFlick infection chain and CosmicPulse backdoor in recent attacks.

Summary

Russian state-sponsored APT Star Blizzard, believed to be subordinate to the FSB, has updated its tactics with the RedFlick malware delivery technique. This method involves a password-protected archive containing a malicious shortcut file disguised as a PDF, which executes a script to download the CosmicPulse backdoor. The group has been targeting Ukrainian entities, international NGOs, governments, and financial institutions supporting Ukraine, employing large-scale phishing campaigns from compromised websites.

Full text

Russian state-sponsored APT Star Blizzard has updated its tactics, techniques, and procedures (TTPs) in recent attacks to evade detection, Microsoft says. Believed to be subordinate to the Russian Federal Security Service (FSB) Centre 18, Star Blizzard is known for launching targeted spear-phishing campaigns against academia, defense, governmental organizations, NGOs, and think tanks, and for using the ClickFix technique and the DarkSword iOS exploit kit. In attacks observed this year, the APT has been relying on large-scale phishing attacks and a new malware delivery technique dubbed RedFlick, which requires a single user interaction for malware execution. If the recipient responds to the initial phishing email, Star Blizzard sends a second message containing a password-protected RAR or ZIP archive that triggers the malware delivery. The state-sponsored group has been using the technique in attacks against Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have been providing support to Ukraine. Star Blizzard, Microsoft says, has been creating accounts on compromised websites to send tens to hundreds of phishing emails per campaign, likely through a mass-mailing phishing platform.Advertisement. Scroll to continue reading. Between January and August 2026, the APT launched over a dozen campaigns containing a RedFlick lure attachment, posing either as Ukrainian authorities or a reputable think tank or NGO. The emails were crafted to appear to come from within the targeted organization. In January, Star Blizzard began sending phishing emails with a malicious Virtual Hard Disk (VHDX) container attached. Inside, the group embedded the RedFlick payload: a shortcut file disguised as a PDF document that, when clicked, opens a decoy file while quietly executing a background script. That script fetches an MSI installer, configures scheduled tasks for persistence, and launches the NoroBot or BaitSwitch downloader to deliver the CosmicPulse Python backdoor. In April, Star Blizzard started using three RedFlick scheduled tasks for persistence, masquerading as Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor. In July, the APT was seen using a multistage execution chain that involved a PowerShell payload executed by the malicious LNK file. The PowerShell attempted to fetch another MSI file that attempted to create two additional scheduled tasks. “Star Blizzard’s shift from ClickFix-based delivery chains to VHDX files, expanded use of scheduled tasks for persistence, and concealment of payloads within PDF files demonstrate the actor’s continued ability to adapt their delivery methods in response to evolving defenses,” Microsoft notes. Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining Related: Four Cyber Threats Harboring Big Plans for the Future Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Reco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary RecordsGoogle Warns of ShinyHunters’ Fresh Oracle PeopleSoft CampaignKiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Latest News Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitShinyHunters Defiant After FBI Calls on Members to Come ForwardHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLTrump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI DevelopmentOpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer ConferenceDARPA Selects Xint to Use AI in Securing Military Messaging AppsNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksRemoteThreat Launches With $7 Million for Offensive Operations Platform Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveSherman Chu joined The Port Authority of New York & New Jersey as CISO.Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — CosmicPulse
  • malware — NoroBot
  • malware — BaitSwitch
  • mitre_attack — T1566.002
  • mitre_attack — T1059.001
  • mitre_attack — T1053.005

Entities

Star Blizzard (threat_actor)Microsoft (vendor)