Russian State Hackers Use New RedFlick Technique to Push Malware

The landscape of advanced persistent threats has shifted once again as cybersecurity researchers uncover a sophisticated delivery mechanism deployed by the Russian state-sponsored threat group known as Star Blizzard. Active for nearly a decade, the hacking collective has refined its operations by introducing a new infection vector called "RedFlick." Designed to automate the deployment phase of cyberattacks and minimize the necessity of victim interaction, RedFlick serves as the launchpad for the group’s signature CosmicPulse backdoor. According to recent telemetry from Microsoft threat intelligence researchers, this development highlights the persistent evolution of Russian cyber espionage operations, which continue to focus heavily on geopolitical adversaries, critical infrastructure providers, and international organizations supporting Ukraine.
The emergence of RedFlick underscores a broader operational transition toward streamlined automation within the threat actor’s methodology. While the underlying concepts of the technique are familiar within the cybersecurity domain, their application by Star Blizzard represents a novel, highly effective approach to payload delivery. By reducing the number of manual steps required by a targeted individual to execute malicious code, the hackers have significantly lowered the friction traditionally associated with successful spear-phishing campaigns.
Anatomy of a RedFlick Attack Chain
The lifecycle of a RedFlick attack typically begins with a multi-tiered social engineering campaign. Victims first receive a seemingly innocuous initial phishing message—often framed as a professional invitation, conference notice, or administrative document. This initial contact is designed to build rapport and lower the recipient’s guard. Once established, a secondary message is sent, containing a password-protected ZIP or RAR archive intended to bypass standard automated email security gateways.
Inside this archive lies a VHDX virtual disk image containing a Windows Shortcut (.LNK) file meticulously disguised as a standard Portable Document Format (PDF) document. When the unsuspecting target attempts to open the file, the malicious shortcut secretly launches a command execution sequence inside a hidden command prompt window. Simultaneously, to maintain the illusion of legitimacy and prevent immediate panic or suspicion, a decoy PDF document is rendered and displayed on the victim’s screen.

Behind the scenes, the executed commands rapidly download and install an MSI package onto the compromised system. This installer establishes a series of distinct scheduled tasks configured to pose as legitimate operating system maintenance components. By fragmenting the execution logic across multiple scheduled tasks with specialized roles, the threat actors can successfully evade detection by legacy antivirus solutions and behavioral monitoring tools at different stages of the infection lifecycle.
Deploying the CosmicPulse Backdoor
The culmination of the RedFlick execution chain relies on an intermediate downloader known variously as NOROBOT or BAITSWITCH, which is packaged as a Windows Control Panel applet (.cpl). Once active, this downloader retrieves and executes the ultimate payload: the CosmicPulse backdoor.
To successfully execute without raising security alerts, BAITSWITCH downloads two separate ZIP archives. One of these archives contains a legitimate, portable Python 3.8 64-bit software package alongside a custom Python script that functions as a specialized bootstrapper for CosmicPulse. Microsoft researchers detailed this intricate process, noting that the bootstrapper reads an encrypted configuration key from the Windows registry, recovers it using an embedded key processed via AES-ECB (Advanced Encryption Standard in Electronic Codebook) mode, and subsequently decodes the heavily obfuscated CosmicPulse payload in system memory.
Once decrypted and loaded, CosmicPulse provides the operators with robust remote access capabilities. These capabilities mirror those documented by Google’s Threat Analysis Group in late 2025, enabling the attackers to execute arbitrary, attacker-supplied Python code, harvest sensitive documents, and deploy additional malicious binaries directly onto the infected machine.
Chronology and Evolution of Star Blizzard Operations

To understand the gravity of the RedFlick technique, it is essential to examine the historical trajectory of Star Blizzard, a group also tracked by various security firms under aliases such as ColdRiver, Callisto, and SEADOWN. Active continuously since at least 2017, the group has transitioned from rudimentary credential-harvesting operations to complex, multi-stage espionage campaigns targeting high-profile individuals and organizations worldwide.
In the years following its initial emergence, Star Blizzard established a reputation for relentless innovation in payload delivery mechanisms. The group has historically experimented with a wide array of tactics, including the abuse of legitimate cloud services, the manipulation of messaging applications like WhatsApp to target high-value diplomats, and the deployment of the "ClickFix" social engineering framework, which tricked users into executing PowerShell scripts under the guise of resolving browser errors.
The introduction of RedFlick in early 2026 represents a maturation of these concepts. Unlike ClickFix, which demanded active, multi-step manual compliance from the victim—such as opening a run dialog and pasting malicious code—RedFlick requires only that the target open a malicious shortcut file, thereby handing over complete control of the automation process to the attackers.
Targeting Profiles and Scale of Operations
Data compiled by Microsoft since the beginning of 2026 reveals the sheer scale of Star Blizzard’s ongoing offensive operations. Security telemetry indicates that the threat group has launched at least 13 distinct, large-scale phishing campaigns over a relatively brief period. These operations have successfully targeted more than 100 distinct organizations spanning critical geographic regions, primarily concentrated within the United States and the United Kingdom.
Beyond Western governmental and corporate entities, the primary focus of Star Blizzard remains closely aligned with Russian strategic geopolitical interests. The RedFlick campaigns have systematically targeted Ukrainian citizens, military personnel, and government institutions. Furthermore, the net has been cast wide to snare international non-governmental organizations (NGOs), prominent think tanks, foreign policy research centers, and financial institutions that have provided political, logistical, or financial support to Ukraine following the 2022 invasion.

Despite adopting advanced technical methodologies such as VHDX files and multi-staged Python bootstrappers, Star Blizzard continues to rely on certain foundational tradecraft. The group frequently masquerades as trusted professional contacts, academic peers, or colleagues, utilizing free, consumer-grade email hosting providers to dispatch initial spear-phishing lures. This hybrid approach—combining low-tech social engineering with high-tech, evasive payload delivery—remains a hallmark of their persistent threat model.
Industry and Official Responses
In response to the persistent threat posed by Star Blizzard, international cybersecurity firms, law enforcement agencies, and technology giants have ramped up collaborative mitigation efforts. Over the past several years, joint initiatives involving Microsoft’s Threat Intelligence Center and federal law enforcement bodies, such as the U.S. Department of Justice, have successfully seized numerous spear-phishing domains and infrastructure assets utilized by the group to disrupt their operational pipelines.
Security analysts emphasize that traditional signature-based antivirus solutions often struggle to keep pace with rapidly mutating threat vectors like RedFlick, particularly given their reliance on legitimate binaries like Python and standard administrative MSI installers to execute malicious payloads. Consequently, cybersecurity leaders strongly advocate for a defense-in-depth posture.
Recommended Mitigations and Defense Strategies
Enterprise security teams and high-risk organizations are urged to implement comprehensive countermeasures to protect against Star Blizzard’s evolving tactics. Key defensive recommendations include:
.jpg)
- Phishing-Resistant Authentication: Deploying hardware-backed security keys (FIDO2/WebAuthn) to eliminate the efficacy of credential-harvesting and adversary-in-the-middle phishing attacks.
- Conditional Access Policies: Enforcing strict device health and location checks before granting users access to sensitive corporate or institutional resources.
- Advanced Endpoint Detection and Response (EDR): Ensuring that EDR solutions are deployed and actively running in "block mode." This ensures that suspicious artifacts and anomalous behaviors—such as hidden command prompt windows spawning MSI installers—are automatically terminated even if initial antivirus signatures fail to flag the files.
- Enhanced Email Protection Gateways: Utilizing robust email security filters capable of inspecting, sandboxing, and stripping high-risk archive formats, including password-protected ZIP, RAR, and VHDX virtual disk files.
- Independent Verification: Establishing organizational policies that require employees and high-profile individuals to independently verify unusual requests or document shares through out-of-band communication channels using established, trusted contact details.
Broader Implications and Future Outlook
The deployment of the RedFlick technique by Star Blizzard highlights a troubling reality in modern cybersecurity: state-sponsored threat actors are continually optimizing their attack chains to maximize efficiency and evade detection. By reducing the human element required to execute complex malware strains like CosmicPulse, groups like Star Blizzard can scale their operations while maintaining a high degree of operational security.
As geopolitical tensions remain elevated, state-backed cyber espionage operations are expected to grow increasingly sophisticated. Organizations operating in government, defense, research, and financial sectors must remain vigilant, treating spear-phishing not merely as an IT annoyance, but as a critical, high-consequence entry point for advanced espionage campaigns. The shift toward automated, file-less, and multi-staged delivery mechanisms signals that the future of defense will heavily rely on automated machine-speed detection and zero-trust architectures capable of intercepting attacks before malicious payloads can touch disk.






