Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked by Microsoft as RedFlick.
Microsoft Threat Intelligence reported that the group, which CISA attributes to Russia’s Federal Security Service (FSB) Center 18, conducted at least 13 phishing campaigns between January and August 2026.
The activity affected more than 100 organizations, primarily in the United States and United Kingdom, with targets including Ukrainian institutions, governments, NGOs, think tanks, research organizations, diplomatic staff, media entities, and financial institutions connected to support for Ukraine.
Star Blizzard historically relied on tightly targeted spear-phishing campaigns, often impersonating political figures, academics, or diplomatic contacts.
In 2026, however, the actor broadened its initial outreach, sending tens to hundreds of emails per campaign to identify recipients willing to engage before delivering malware.
The lures commonly impersonated invitations to closed-door policy discussions, international conferences, financial events, and Ukraine-related forums.
In some cases, phishing emails appeared to originate from internal contacts or reputable organizations known to the intended target.
A key operational change involved the use of email accounts created on compromised websites, including sites hosted on cPanel and WordPress infrastructure.
Microsoft assessed with high confidence that Star Blizzard compromised those websites to create and operate sender accounts, helping the actor avoid depending exclusively on free email providers and increasing the credibility of phishing messages.
The RedFlick chain begins only after a recipient responds to an attachment-free phishing email.
Star Blizzard then sends a follow-up message containing a password-protected ZIP or RAR archive, while providing the password as an image embedded in the email.
This delivery method complicates automated email inspection because security products may be unable to scan encrypted archive contents before they reach the endpoint.
RedFlick Backdoor
The follow-up also arrives within an apparently legitimate email conversation, increasing the likelihood that a recipient will regard the attachment as an expected document.
Fieldeffect Researchers observed that, RedFlick uses password-protected archives, scheduled tasks, WebDAV, and disguised Windows components to install the CosmicPulse backdoor on targeted systems.
Earlier 2026 campaigns used ZIP archives containing VHDX virtual disk images. The VHDX file included a malicious Windows shortcut, or LNK, disguised as a PDF document, a hidden BAT script, and a decoy PDF.
When a victim launched the shortcut, the script opened the decoy while using legitimate Windows binaries and SSH functionality to download and execute a remote MSI installer.
Beginning in April, RedFlick installers moved beyond creating a single scheduled task.
Microsoft observed MSI installers creating three scheduled tasks masquerading as benign Windows or network-management components: Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.
The first task sends basic host data, including the computer or network name and username, to command-and-control infrastructure. It can also invoke attacker-controlled DLLs remotely through Control_RunDLL and Shell32.dll.
A second task enables the WebClient functionality required to access WebDAV paths, allowing Windows to retrieve remote resources over HTTP or HTTPS while treating them like network shares.
The third task uses control.exe to retrieve and execute a remote Control Panel applet, or CPL file. That component functions as a CosmicPulse downloader, installing a Python environment, decrypting the final payload, and launching the CosmicPulse backdoor.
The malware is also publicly known as YESROBOT, while its downloader has been referred to as NOROBOT or BAITSWITCH.
In July, Star Blizzard introduced another RedFlick variation that nested a password-protected RAR archive inside a ZIP file.
The archive exposed an LNK file which used conhost.exe and curl to download a PDF from actor-controlled infrastructure.
Rather than serving only as a decoy, the PDF concealed Base64-encoded data. A PowerShell command searched the downloaded file for a cAB marker, extracted 208 bytes of encoded content, decoded it, and executed the result to download another MSI installer.
The installer then attempted to create additional scheduled tasks and deploy the CPL-based CosmicPulse downloader.
Defenders should investigate password-protected archives delivered after attachment-free email exchanges, especially where passwords are embedded in images or senders claim an attachment was previously omitted.
Endpoint telemetry is critical because mail-layer controls may have limited visibility into encrypted archives.
High-value hunting signals include VHDX mounting, LNK files masquerading as PDFs, conhost.exe launching curl, suspicious msiexec.exe behavior, PowerShell extracting content from PDFs, ssh.exe executed with PermitLocalCommand, WebDAV activity, and creation of the three scheduled-task names associated with RedFlick.
Microsoft also recommends phishing-resistant authentication, Conditional Access, Safe Links, Safe Attachments, endpoint detection and response in block mode, and controls that prevent execution of obfuscated scripts.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

