Russian state-linked hacking group Star Blizzard has adopted a delivery method that automates more of its malware installation process. Microsoft researchers say RedFlick malware attacks use deceptive file attachments to install the group’s CosmicPulse backdoor.

The approach still depends on phishing and a victim opening a malicious file. However, it requires fewer manual steps than the group’s previous ClickFix campaigns.

Phishing Messages Lead to a Disguised Shortcut

The attack begins with an email that presents a plausible reason to engage, such as an invitation. A follow-up message then delivers a password-protected ZIP or RAR archive.

Inside that archive, the attackers place a VHDX virtual disk containing a Windows shortcut disguised as a PDF.

When the victim opens the shortcut, it launches a hidden command and displays a decoy PDF. Meanwhile, the command downloads and runs an MSI installer, starting the next stage of infection.

RedFlick therefore represents a new delivery approach for Star Blizzard, rather than an entirely new cybersecurity technique.

Three Scheduled Tasks Divide the Installation Process

The installer creates three scheduled tasks with names that resemble ordinary maintenance functions. Each handles a different part of the attack.

Internet Quality Test Connection sends computer, network and username information to the attackers. It can also execute a remote DLL.

Network Configuration Manager prepares Windows’ WebDAV functionality. This allows the system to access remote web resources through file-style paths.

System Health Monitor uses the Windows utility control.exe to run a remotely hosted payload.

By splitting these activities across separate tasks, the attackers aim to make different stages harder to detect.

Downloader Installs the CosmicPulse Backdoor

The next component arrives as a Control Panel applet with a .cpl extension. Microsoft identifies this downloader as NOROBOT, also known as BAITSWITCH.

It retrieves two ZIP archives. One contains a 64-bit Python 3.8 package and a Python bootstrapper that prepares CosmicPulse to run.

The bootstrapper recovers an encrypted key from the Windows registry. It then uses that key to decode the backdoor payload.

According to Microsoft, CosmicPulse retains its previously documented capabilities. These include running attacker-supplied Python code, downloading and executing files, and retrieving documents from infected systems.

Once the victim opens the disguised shortcut, the remaining installation stages proceed automatically. In contrast, Star Blizzard’s ClickFix attacks required victims to carry out several manual actions.

Campaigns Target Organizations Supporting Ukraine

Microsoft says it observed at least 13 distinct large-scale Star Blizzard phishing campaigns from the beginning of 2026. Together, they affected more than 100 organizations, primarily in the United States and the United Kingdom.

Within that activity, RedFlick malware attacks targeted Ukrainian individuals and institutions, alongside international organizations supporting Ukraine politically or financially.

Targets included nongovernmental organizations, think tanks, government bodies and financial institutions.

Despite the delivery changes, Star Blizzard continues to impersonate trusted contacts and organizations. It also still uses free email providers to send phishing messages.

Microsoft Recommends Layered Defenses

Microsoft advises organizations to combine phishing-resistant authentication, Conditional Access policies and email protection.

Additionally, recipients should verify suspicious messages through established contact details, rather than relying on information in the message itself.

The company also recommends endpoint detection and response tools operating in block mode. These can provide another opportunity to stop malicious components when antivirus protection misses them.


0 responses to “RedFlick Malware Attacks Deliver Russian Backdoor Through Fake PDFs”