Russian state-sponsored threat actor Star Blizzard has expanded its use of a streamlined malware delivery technique dubbed RedFlick, turning it into the backbone of large-scale phishing campaigns that install the group’s custom CosmicPulse backdoor on Windows systems[1][2][10].
Researchers say the campaigns begin with relatively innocuous-looking emails that establish rapport with targets before delivering any malware, a tactic designed to bypass automated scanning and exploit human trust[1][2][11]. Once a recipient responds to the initial outreach, Star Blizzard typically sends a follow-up message containing a password-protected RAR or ZIP archive, with the password often embedded as an image in the email body to evade text-based detection[2][5][11]. Inside the archive, victims encounter either a virtual hard disk (VHDX) file or a shortcut (LNK) disguised as a PDF document, and a single click on that lure is enough to trigger the RedFlick infection flow[2][6][12].
The RedFlick chain relies heavily on legitimate Windows tools, or “living off the land” binaries, to stay under the radar of endpoint defenses[1][4][6]. When the victim opens the booby-trapped LNK file, it launches c-o-n-h-o-s-t.exe and c-m-d.exe to run a batch script that opens a decoy document while quietly invoking ssh.e-x-e or curl.e-x-e to download an MSI installer from attacker-controlled infrastructure[4][6][12]. That installer creates multiple scheduled tasks masquerading as benign system or network utilities—names observed in recent campaigns include Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor[2][12]. The tasks then use control.e-x-e and Control Panel applet DLLs, along with WebDAV UNC paths, to pull down and execute a CosmicPulse downloader, ultimately installing the Python-based backdoor for persistent remote access[1][4][6].
Between January and August 2026, Star Blizzard is reported to have run more than a dozen RedFlick-enabled campaigns, frequently impersonating Ukrainian authorities, international NGOs, and prominent Western think tanks in their phishing lures[2][12][15]. Public reporting indicates the actor has targeted over 100 organizations, including Ukrainian institutions, Western governments, and policy organizations seen as supportive of Ukraine, in operations that blend social engineering with infrastructure hosted on compromised WordPress and cPanel sites for command-and-control traffic[3][7][15]. By decoupling the initial contact from the eventual malware delivery and reducing the required user interaction to a single click, RedFlick offers Star Blizzard greater scalability and improved chances of slipping past defensive controls[1][2][5].
Star Blizzard, also known by aliases including SEABORGIUM and COLDRIVER in earlier reporting, has been publicly attributed by the United Kingdom, United States, and allied governments as a cyber-espionage unit subordinate to Centre 18 of Russia’s Federal Security Service (FSB)[9]. The group’s CosmicPulse backdoor—tracked in some sources as YESROBOT—provides long-term access to infected hosts, supports host reconnaissance, and enables retrieval and execution of additional payloads over WebDAV and other remote resources[6][9][12]. Recent activity underscores Star Blizzard’s continued focus on political, academic, and civil-society targets linked to Russia’s strategic interests, particularly those involved in Ukraine-related policy and support[1][3][15].
For defenders, the RedFlick campaigns highlight the need to scrutinize password-protected archives delivered in follow-up emails, monitor for suspicious scheduled tasks that mimic network or health-monitoring components, and investigate unexpected use of tools such as control.exe, ssh.exe, and WebDAV connections originating from user workstations[4][6][12]. Organizations in government, research, and non-profit sectors—especially those active on Ukraine or broader geopolitical issues—should review email workflows for targeted social engineering, tighten controls around external correspondence, and enhance visibility into endpoint task scheduling to spot the subtle, low-interaction infection chains that Star Blizzard now favors.
References
- Star Blizzard refines phishing and malware delivery with …
- Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain …
- Russia’s Star Blizzard Targets 100+ Organizations With Fake …
- windowsforum.com › news › star-blizzard-redflickStar Blizzard RedFlick Phishing Uses Windows Tools to Deploy …
- Star Blizzard scala il phishing: RedFlick colpisce oltre 100 organizzazioni
- cyfar.ca · posts · star-blizzard-refines-phishing-and-malwareStar Blizzard refines phishing and malware delivery with the…
- Star Blizzard RedFlick Campaign: Russian FSB Targets 100 …
- Star Blizzard | Mallory
- Microsoft Threat Intelligence on X
- Russian Hackers Wait for Victims to Reply Before Sending the Real Malware
- Star Blizzard Expands Phishing With RedFlick and … – Mallory
- aviatrix.ai › threat-research-center › star-blizzardStar Blizzard RedFlick Technique: Russian APT Evolves …