Menu
CYBERSECURITY NEWS

Star Blizzard Uses RedFlick to Deploy CosmicPulse Malware in New Phishing Campaigns

Uday Patil Sep 30, 2026 6 min read 3 views
Star Blizzard Uses RedFlick to Deploy CosmicPulse Malware in New Phishing Campaigns

Star Blizzard RedFlick campaigns are giving the Russian state-linked threat actor a more streamlined way to deliver its CosmicPulse backdoor, as Microsoft tracks a shift toward larger-scale phishing and more automated malware deployment during 2026.

Microsoft Threat Intelligence says Star Blizzard has changed several parts of its tradecraft since January, including moving beyond highly targeted spear-phishing campaigns, using accounts created on compromised websites to send malicious messages, and introducing a technique Microsoft calls RedFlick.

The activity has targeted Ukrainian individuals and institutions along with international NGOs, Western think tanks, governments and financial organizations connected to political or financial support for Ukraine. Microsoft says it observed the activity affecting more than 100 organizations, primarily in the United States and United Kingdom.

Star Blizzard RedFlick Reduces the Steps Needed to Infect a Target

One of the most significant changes is how Star Blizzard delivers CosmicPulse.

Earlier infection chains relied on ClickFix-style social engineering that required victims to perform several actions before malware could be installed. Microsoft says the RedFlick infection flow reduces that friction and can progress after a single user interaction with the malicious lure.

The change does not eliminate social engineering. Victims are still initially approached through phishing emails, often followed by a password-protected RAR or ZIP archive after the recipient engages with the attacker.

What changed is the malware-delivery mechanism behind the lure. Once execution begins, RedFlick uses Windows components and scheduled tasks to establish persistence and retrieve additional payloads.

From a Fake PDF to CosmicPulse

Microsoft documented multiple variations of the infection chain during 2026. In a January campaign, Star Blizzard delivered a malicious Virtual Hard Disk file, or VHDX, inside a password-protected ZIP archive.

The VHDX contained a malicious LNK file disguised as a PDF along with a hidden directory holding a BAT script and a legitimate decoy document. When the victim opened the shortcut, Windows processes were used to launch the embedded script while displaying the decoy PDF.

According to Microsoft, the script then invoked Windows SSH functionality to retrieve and execute a remotely hosted MSI installer.

That installer created a scheduled task that used control.exe to download and execute a remotely hosted CosmicPulse downloader disguised as a Control Panel applet.

StageObserved activity
Initial contactPhishing email designed to start a conversation with the target
Follow-upPassword-protected RAR or ZIP archive containing the malicious lure
ExecutionVHDX and malicious LNK disguised as a PDF initiate the infection flow
Payload deliveryRemote MSI installer creates scheduled tasks and retrieves additional components
Final malwareCosmicPulse backdoor is downloaded, persisted and executed

RedFlick Uses Multiple Scheduled Tasks for Persistence

By April 2026, Microsoft observed another change in the RedFlick technique. Instead of creating a single scheduled task, Star Blizzard’s MSI installer began creating three tasks masquerading as legitimate Windows network and system functions.

The first task can send basic information about the infected computer to attacker-controlled infrastructure and invoke a remote DLL. Microsoft says the task uses a WebDAV UNC path, allowing the remote resource to be accessed over HTTP rather than through a traditional SMB network share.

A second task supports the WebDAV execution chain by activating the Windows functionality required to process the remote path.

The third task, disguised as a system-health function, uses control.exe to access an attacker-controlled remote location and execute the next stage. Microsoft observed CosmicPulse being delivered through this scheduled-task infrastructure in at least one incident.

This approach is notable because the attackers are not relying on an obviously malicious standalone executable for every stage. Instead, legitimate Windows components are incorporated into the delivery chain, making behavioral detection and investigation especially important.

CosmicPulse Is a Python-Based Backdoor

The final payload in these campaigns is CosmicPulse, a custom backdoor Microsoft has previously associated with Star Blizzard.

The CosmicPulse downloader first retrieves two ZIP archives. One contains a 64-bit Python 3.8 environment and a Python bootstrapper, while another contains the encrypted CosmicPulse payload.

Microsoft says the downloader writes an encrypted AES key into the Windows registry under HKEY_CURRENT_USER\Software\Classes\.mollis. The bootstrapper later recovers the key and uses it to decrypt the malware payload.

Microsoft has observed small changes to CosmicPulse since January 2026 that appear designed to avoid existing signatures, while the backdoor’s core purpose and capabilities have remained broadly consistent.

Star Blizzard Has Expanded Its Phishing Scale

The malware changes are occurring alongside a broader shift in how Star Blizzard chooses and approaches victims.

Historically, the group has been known for carefully prepared spear-phishing campaigns in which attackers research their targets, impersonate trusted contacts and build rapport before delivering credential-stealing links.

In 2026, Microsoft observed Star Blizzard moving from exclusively targeted spear phishing toward larger initial-contact campaigns as well. The actor has also used compromised websites to create email accounts for malicious outreach, adding another layer of legitimacy to phishing infrastructure.

The United Kingdom’s National Cyber Security Centre, together with international partners, has previously assessed that Star Blizzard is almost certainly subordinate to Centre 18 of Russia’s Federal Security Service.

Star Blizzard is also known by names including SEABORGIUM, Callisto Group and COLDRIVER across different security organizations.

The campaign fits the broader pattern of state-backed cyberespionage activity covered in CyberUpdates365’s Nation-State and APT Cyber Warfare hub, where phishing, credential theft and persistent access remain important entry points for intelligence-focused operations.

What Security Teams Should Look For

  • Unexpected password-protected ZIP or RAR archives arriving after an unsolicited email conversation.
  • VHDX files or LNK shortcuts masquerading as PDF documents.
  • Unexpected use of msiexec.exe, control.exe, SSH or WebDAV-related Windows components.
  • New scheduled tasks with names resembling legitimate network, system-health or configuration functions.
  • Suspicious outbound connections associated with recently created scheduled tasks.
  • Unexpected Python runtime components or registry activity associated with unfamiliar user-level applications.

Microsoft Defender users can also look for detections including Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse and Backdoor:Python/CosmicPulse, along with alerts for suspicious MSI, LNK and Control Panel activity documented in Microsoft’s threat research.

Organizations targeted by Russian intelligence-linked actors should also review their broader exposure to phishing and credential theft. CyberUpdates365 previously covered FSB-linked cyberespionage activity involving Void Blizzard; that is a separate threat actor, but it highlights why organizations in government, policy and Ukraine-related sectors remain attractive intelligence targets.

For organizations handling sensitive policy, diplomatic or Ukraine-related information, the immediate priority is to investigate suspicious archive-based phishing, review newly created scheduled tasks and verify unusual WebDAV or remote payload activity rather than relying solely on traditional malware signatures.

Official and Primary Sources

Microsoft Threat Intelligence — Star Blizzard Refines Phishing and Malware Delivery With the RedFlick Technique

UK NCSC — Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-Phishing Campaigns

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.