Star Blizzard Rebuilds Its Phishing Playbook Around the RedFlick Malware Chain

Microsoft links Star Blizzard to RedFlick phishing attacks on Ukraine allies using VHDX files and scheduled tasks to deploy CosmicPulse backdoor.

Star Blizzard Rebuilds Its Phishing Playbook Around the RedFlick Malware Chain
APT

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Microsoft has documented a shift in the delivery tactics of Star Blizzard, a Russian state-sponsored threat actor associated with the Federal Security Service’s Centre 18.

Between January and August 2026, the group conducted more than a dozen campaigns using RedFlick-themed infection chains. The operations targeted Ukrainian organizations and individuals, alongside international entities providing political, financial, or institutional support to Ukraine.

The campaigns combined carefully constructed impersonation, password-protected archives, malicious virtual disk containers, and scheduled tasks. Successful execution ultimately enabled the deployment of CosmicPulse, a Python backdoor.

Ukraine-focused campaigns reached an international target set

Star Blizzard directed the RedFlick campaigns at academia, defense organizations, government bodies, nongovernmental organizations, think tanks, and financial institutions. Ukrainian targets were central, but the activity extended to organizations abroad whose work supported Ukraine.

The phishing messages impersonated Ukrainian authorities, established think tanks, or NGOs. Some were written to appear as though they originated within the recipient’s own organization, increasing the likelihood that the message would survive an initial credibility check.

According to reporting on Microsoft’s findings, Star Blizzard created accounts on compromised websites and used them to distribute tens or hundreds of messages during each campaign. The scale suggests the possible use of a mass-mailing phishing platform, although the specific platform has not been identified.

Star Blizzard is also known for ClickFix attacks and the DarkSword iOS exploit kit. The RedFlick operations show the actor moving beyond a single delivery method rather than abandoning social engineering.

A reply turns reconnaissance into malware delivery

The operation begins with an initial phishing email, but the malicious attachment does not necessarily arrive in that first message. Star Blizzard waits for the recipient to reply before sending a follow-up containing a password-protected RAR or ZIP archive.

This conversational structure gives the attacker several advantages. A response confirms that the address is active, indicates that the recipient has engaged with the pretext, and creates an email thread that may appear more trustworthy than an unsolicited attachment.

It can also complicate defensive analysis. The initial message may contain no overtly malicious file, while the harmful content arrives only after the target has interacted with the sender.

RedFlick still requires one user action for execution. The recipient must open the delivered content, so the chain is not a zero-click compromise. However, the combination of impersonation, an established conversation, and password-protected archives is designed to make that action more likely.

Passwords also create an inspection challenge for security controls that cannot automatically extract and analyze encrypted archive contents. No specific email-security product or affected version has been disclosed.

VHDX containers concealed shortcuts, scripts, and MSI installers

In January, Star Blizzard began delivering malicious VHDX containers inside its phishing packages. VHDX is a virtual hard disk format that Windows can mount, allowing its contents to appear much like files on another drive.

Inside the container, the attacker placed a shortcut disguised as a PDF document. Opening the shortcut displayed decoy content while a script ran in the background.

That script retrieved an MSI installer, which established scheduled tasks for persistence and launched either the NoroBot or BaitSwitch downloader. The downloader then delivered CosmicPulse, a backdoor written in Python.

The visible document helps preserve the illusion that the user opened a legitimate PDF. Meanwhile, the actual execution path passes through a shortcut, scripting, an MSI package, scheduled tasks, and a dedicated downloader.

This layered design separates the phishing artifact from the final backdoor. It also gives Star Blizzard multiple opportunities to modify intermediate stages without rebuilding the entire operation.

No hashes, domains, IP addresses, archive names, or file paths have been disclosed. There is therefore no reported set of high-confidence network or file indicators that defenders can use to identify every RedFlick campaign.

Scheduled tasks became a recurring persistence mechanism

Scheduled tasks feature prominently across the observed chains. In April, three tasks used names intended to resemble ordinary Windows maintenance or monitoring components:

  • Internet Quality Test Connection
  • Network Configuration Manager
  • System Health Monitor

The names are generic enough to blend into a task inventory, particularly in environments where administrators do not maintain a baseline of approved scheduled jobs.

In July, Microsoft observed a multistage variation in which a malicious LNK shortcut launched PowerShell. The script attempted to retrieve another MSI installer, which in turn tried to create two additional scheduled tasks.

The available reporting does not identify the names of those two tasks or confirm whether every installation attempt succeeded. It does show that Star Blizzard repeatedly incorporated task creation into its execution and persistence strategy.

Task names alone are not proof of compromise. Defenders should evaluate their creation time, executable path, command-line arguments, parent process, associated user account, and any nearby PowerShell or MSI activity.

A task with a plausible name becomes considerably more suspicious when it launches content from a user-writable directory, appears immediately after an archive or VHDX is opened, or follows execution of an unexpected LNK file.

CosmicPulse is the final reported payload

The principal reported impact is the installation of malware, persistence through scheduled tasks, and deployment of the CosmicPulse Python backdoor. The precise capabilities of CosmicPulse are not described, so its supported commands, communications protocol, and data-access functions are not known.

No severity rating has been assigned. This activity is an intrusion campaign rather than a disclosed software vulnerability, and no CVE, affected product-version range, or CISA Known Exploited Vulnerabilities catalog entry is associated with it.

Microsoft assesses that the changes reflect Star Blizzard’s response to improving defenses. In particular, the actor has moved away from relying on ClickFix-based delivery, increased its use of scheduled tasks, and used PDF-themed content to conceal malicious execution.

The result is not a fundamentally novel phishing model. Its effectiveness comes from combining recognizable techniques in a carefully sequenced chain: trusted impersonation, recipient engagement, encrypted archives, misleading file presentation, script execution, installer abuse, persistence, and a final backdoor.

Defenders should hunt for the chain, not one file

Microsoft did not provide a specific mitigation package for RedFlick. There is also no vendor patch because the reported campaigns do not center on a software flaw.

Organizations can nevertheless investigate the behaviors described in the campaigns. Priority areas include unexpected VHDX files delivered by email, LNK files presented as PDFs, PowerShell launched from shortcuts, MSI retrieval following archive access, and newly created scheduled tasks with generic system-oriented names.

Email teams should also examine follow-up messages that deliver password-protected RAR or ZIP files after an employee replies to an external sender. Messages impersonating Ukrainian authorities, NGOs, or think tanks deserve additional scrutiny when directed at organizations supporting Ukraine.

Because the initial email may be benign on its own, reviewing only the first message can miss the harmful stage. Incident responders should reconstruct the complete thread and correlate it with endpoint activity.

Where one of the reported task names is found, responders should avoid treating deletion as sufficient remediation. The surrounding execution chain may include an MSI installer, a downloader such as NoroBot or BaitSwitch, and the CosmicPulse backdoor. The host should be examined for each stage.

The absence of published infrastructure indicators makes behavioral visibility especially valuable. RedFlick’s components may change, but the observed transition from conversational phishing to shortcut execution, MSI installation, scheduled-task persistence, and backdoor delivery provides a more durable basis for detection.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →