Russian state hackers use new RedFlick technique to push malware

The Russian-linked threat actor known as Star Blizzard has significantly evolved its operational methodology throughout 2026, pivoting to a sophisticated delivery mechanism identified by security researchers as “RedFlick.” This new tactic is designed to streamline the deployment of the group’s signature CosmicPulse backdoor, marking a strategic shift toward increased automation and reduced reliance on manual victim interaction. By integrating virtual disk technologies and multi-stage scheduled tasks, the group has successfully enhanced its ability to infiltrate high-value targets across the United Kingdom, the United States, and beyond, with a specific focus on entities involved in supporting Ukraine.
Evolution of the Star Blizzard Threat Landscape
Active since at least 2017, Star Blizzard—often tracked by intelligence agencies as a prolific cyber-espionage unit—has consistently demonstrated an ability to adapt its infrastructure. The group has historically favored spear-phishing as its primary vector, often masquerading as legitimate contacts, journalists, or representatives of academic institutions to build rapport before deploying malicious payloads.
Over the past three years, the group’s evolution has been marked by a series of high-profile campaigns. In 2025, the group made headlines for its adoption of the “ClickFix” technique, which coerced victims into manually interacting with browser windows to execute malicious scripts. While effective, ClickFix required a high level of victim engagement, which provided security solutions more opportunities to detect the anomalous behavior. RedFlick represents a more silent, automated successor to these earlier efforts, leveraging the native Windows environment to execute code with minimal user oversight.

The RedFlick Infection Chain: A Technical Breakdown
The RedFlick technique is a masterclass in obfuscation. The attack begins with a carefully crafted phishing email, often disguised as an invitation to an event or a request for comment. These emails are typically innocuous, serving as a lure to establish credibility. Once the victim responds, a second email is sent, containing a password-protected archive file, either in ZIP or RAR format.
The security of this method lies in the contents of the archive: a VHDX (Virtual Hard Disk) file. When the user mounts this virtual disk, they are presented with an LNK file icon disguised as a PDF document. This is a critical psychological trigger; the user, expecting a document, clicks the shortcut. Behind the scenes, the LNK file executes a command hidden from the user’s view. While a decoy PDF document is launched to satisfy the victim’s expectation of opening a file, the background process initiates a series of malicious downloads.
The infection process then triggers an MSI (Microsoft Installer) package, which registers three distinct scheduled tasks. These tasks are cleverly named to mimic legitimate system maintenance or security components, allowing them to blend into the background of a standard Windows operating system. By utilizing multiple tasks with staggered execution roles, Star Blizzard ensures that if one part of the chain is flagged by security software, the others remain operational, thereby maintaining persistence within the environment.
The Role of NOROBOT and BAITSWITCH
Once the initial tasks are established, the malware fetches a second-stage downloader, identified in technical reports as NOROBOT and BAITSWITCH. These components arrive in the form of a Control Panel applet (.cpl). The primary function of this module is to retrieve and execute the final-stage payload: the CosmicPulse backdoor.

The delivery of CosmicPulse is particularly notable for its reliance on an embedded Python environment. BAITSWITCH downloads two compressed archives, one of which contains a 64-bit version of Python 3.8 and a specialized bootstrapper script. This bootstrapper is responsible for decrypting the CosmicPulse payload, which is stored in an encrypted state within the Windows registry. By using an AES-ECB (Advanced Encryption Standard in Electronic Codebook mode) decryption process, the attackers ensure that the malware remains obfuscated even if the files are scanned at rest on the disk.
Once active, CosmicPulse provides the attackers with comprehensive control over the infected machine. Its capabilities include the execution of arbitrary Python code, the exfiltration of sensitive documents, and the ability to pull additional malicious tools into the victim’s network.
Chronology of 2026 Operations
The shift to RedFlick is not an isolated development but rather the culmination of an aggressive expansion of Star Blizzard’s activities in 2026. Microsoft security researchers have observed at least 13 large-scale phishing campaigns launched since January 2026.
- Q1 2026: Initial testing of new delivery vectors, moving away from the manual interaction requirements of the previous year’s ClickFix campaigns.
- Q2 2026: Increased integration of VHDX files into the delivery chain to bypass basic email attachment scanning protocols that often struggle with virtual disk formats.
- Q3 2026: Widespread deployment of the RedFlick technique against targets in the defense, diplomatic, and NGO sectors.
- September 2026: Microsoft officially documents the RedFlick technique, identifying the specific interaction between the LNK files, MSI installers, and the CosmicPulse backdoor.
Targeted Sectors and Geopolitical Implications
The targeting profile of these campaigns remains consistent with Star Blizzard’s broader geopolitical objectives. The victims identified by researchers include government agencies, financial institutions, international think tanks, and NGOs that provide political, financial, or humanitarian support to Ukraine.

The use of free email providers for the initial phishing phase highlights the group’s continued reliance on low-cost, high-volume infrastructure. By cycling through hundreds of accounts, they maintain a degree of operational security that makes it difficult for defenders to block the entirety of their infrastructure. The persistence of these attacks suggests that the group is well-resourced and maintains a clear mandate from its handlers to prioritize the collection of intelligence from Western organizations involved in the conflict in Eastern Europe.
Expert Analysis and Mitigation Strategies
From a defensive standpoint, the RedFlick technique highlights the ongoing struggle to balance user convenience with security. The abuse of legitimate Windows features—such as LNK files and scheduled tasks—means that signature-based antivirus solutions are often insufficient.
Security experts emphasize that while the technical sophistication of the malware is noteworthy, the initial entry point remains a human-centric vulnerability. To mitigate the risks posed by Star Blizzard, organizations are urged to move beyond traditional password-based authentication. The implementation of phishing-resistant multi-factor authentication (MFA) and strict Conditional Access policies are deemed essential to preventing initial account compromises.
Furthermore, the deployment of Endpoint Detection and Response (EDR) tools in “block mode” is critical. Unlike passive antivirus, EDR solutions monitor behavioral patterns, such as the unauthorized mounting of virtual disks or the creation of suspicious scheduled tasks. By identifying the behavior of the RedFlick chain rather than just the files themselves, security teams can sever the attack path before the CosmicPulse backdoor is fully deployed.
.jpg)
The Future of AI-Powered Defense
As attackers like Star Blizzard continue to automate their infection chains, the security industry is pivoting toward machine-speed defense. Industry leaders, including those in the cybersecurity summit circuit, are now advocating for a paradigm shift: defenders must be able to validate, decide, and neutralize threats at the same speed as the automated tools being developed by state-sponsored actors.
The rise of RedFlick is a reminder that the threat landscape is not static. As defenses improve, threat actors will inevitably refine their delivery mechanisms to bypass new security controls. Organizations that remain reliant on legacy security protocols will find themselves increasingly vulnerable to these types of high-precision, low-interaction campaigns. Moving forward, the focus for both the public and private sectors must be on proactive threat hunting and the integration of advanced behavioral analytics to stay one step ahead of persistent, well-funded adversaries.






