INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russian State Hackers Employ New RedFlick Malware Technique
| 2026-09-30 20:34 CRITICAL HIGH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor, according to extracted tactical telemetry. This technique was first observed on September 30, 2026, and has since targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially. The attacks begin with a phishing email, followed by a second message containing a password-protected ZIP or RAR archive. Microsoft researchers note that Star Blizzard expanded its phishing operations and streamlined malware delivery in 2026, using tactics such as impersonating trusted contacts or organizations to deliver phishing messages. To mitigate these threats, companies are advised to use phishing-resistant authentication, Conditional Access policies, email protection, and independently verify suspicious messages through established contact details.
Technical Mitigations AI-generated
• Implement phishing-resistant authentication and Conditional Access policies: Companies can use solutions like Microsoft's Azure Active Directory (AAD) to protect users from phishing attacks. AAD provides features such as multi-factor authentication, conditional access controls, and threat intelligence feeds.
• Use email protection and independently verify suspicious messages: Organizations should implement email security solutions that detect and block malicious emails before they reach the user's inbox. Additionally, employees can be trained to verify suspicious messages through established contact details or by contacting IT support directly.
• Deploy endpoint detection and response (EDR) solutions in block mode: EDR solutions like Microsoft Defender Advanced Threat Protection (ATP) can help prevent infections by blocking malicious artifacts even if they manage to evade traditional security controls. Block mode ensures that the solution scans all files, folders, and registry keys for potential threats.
• Monitor system logs and network traffic for suspicious activity: Organizations should monitor their system logs and network traffic for signs of RedFlick malware installation, such as unusual scheduled tasks or command executions in hidden windows. This can help detect and respond to attacks more quickly.
• Implement a robust security information and event management (SIEM) system: A SIEM system like Microsoft's Azure Sentinel can collect and analyze log data from various sources, providing real-time insights into potential threats. It can also alert administrators to suspicious activity and provide recommendations for remediation.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
co•••••.exe
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
October 2025
Star Blizzard, a Russian state actor, has been using the T1059.006 Python backdoor to execute attacker-supplied code and download/run files or retrieve documents from infected systems since October 2025.
Click on any entity below to view its context and source!
tactic
T1059.006 - Python
Attack chain overview
Source: Microsoft
Microsoft notes that the backdoor’s capabilities in the observed attacks remain the same as described in a
report from Google
in October 2025, including the execution of attacker-supplied Python code to download and run files or retrieve documents from infected systems.
organisation
Google
Attack chain overview
Source: Microsoft
Microsoft notes that the backdoor’s capabilities in the observed attacks remain the same as described in a
report from Google
in October 2025, including the execution of attacker-supplied Python code to download and run files or retrieve documents from infected systems.
2026/09/30
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor.
Click on any entity below to view its context and source!
threat_actor
Star Blizzard
The Russian state actor Star Blizzard has been using a new m....
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor.
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed “RedFlick” to deploy its signature CosmicPulse backdoor.
Microsoft researchers say that Star Blizzard expanded its phishing operations and streamlined malware delivery in 2026.
Star Blizzard,
active since 2017
, is known for exploring new payload delivery avenues like
ClickFix
or
WhatsApp
, and for continually developing and deploying
new malware families
.
From a practical perspective, RedFlick only requires the victim to open the malicious shortcut file to trigger an automated infection chain, whereas in the ClickFix attacks, Star Blizzard required victims to take multiple manual actions.
organisation
RedFlick
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor.
Russian state hackers use new RedFlick technique to push malware.
organisation
CosmicPulse
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor.
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed “RedFlick” to deploy its signature CosmicPulse backdoor.
organisation
Microsoft
Microsoft researchers say that Star Blizzard expanded its phishing operations and streamlined malware delivery in 2026.
organisation
ClickFix
Star Blizzard,
active since 2017
, is known for exploring new payload delivery avenues like
ClickFix
or
WhatsApp
, and for continually developing and deploying
new malware families
.
organisation
WhatsApp
Star Blizzard,
active since 2017
, is known for exploring new payload delivery avenues like
ClickFix
or
WhatsApp
, and for continually developing and deploying
new malware families
.
victims
100 organizations
The company says that since the beginning of the year, it has observed at least 13 distinct large-scale phishing campaigns impacting more than 100 organizations, primarily in the United States and the United Kingdom.
organisation
StarBlizzard
Despite changing its tactics, techniques, and procedures, StarBlizzard continues to target users by impersonating trusted contacts or organizations, and still relies on free email providers to deliver phishing messages.
organisation
Conditional Access
Microsoft recommends that companies use phishing-resistant authentication, Conditional Access policies, email protection, and independently verify suspicious messages through established contact details.
infrastructure
Windows
Network Configuration Manager:
prepares Windows’ WebDAV functionality so remote web resources can be accessed through file-style paths.
organisation
Network Configuration
Network Configuration Manager:
prepares Windows’ WebDAV functionality so remote web resources can be accessed through file-style paths.
organisation
Windows’ WebDAV
Network Configuration Manager:
prepares Windows’ WebDAV functionality so remote web resources can be accessed through file-style paths.
organisation
VHDX
The archive contains a VHDX virtual disk with an LNK file disguised as a PDF.
organisation
LNK
The archive contains a VHDX virtual disk with an LNK file disguised as a PDF.
organisation
PDF
The archive contains a VHDX virtual disk with an LNK file disguised as a PDF.
organisation
MSI
VHDX-based attack chain
Source: Microsoft
The commands download and run an MSI installer that creates three scheduled tasks posing as legitimate maintenance components, each with a specific purpose:
Internet Quality Test Connection:
sends the computer/network name and username to the attackers and can execute a remote DLL.
organisation
DLL
VHDX-based attack chain
Source: Microsoft
The commands download and run an MSI installer that creates three scheduled tasks posing as legitimate maintenance components, each with a specific purpose:
Internet Quality Test Connection:
sends the computer/network name and username to the attackers and can execute a remote DLL.
organisation
BAITSWITCH
The next-stage payload is a downloader known as NOROBOT and BAITSWITCH, delivered in the form of a Control Panel applet (.cpl).
organisation
AES
"The bootstrapper reads the encrypted key from the registry, recovers it using an embedded key in AES-ECB mode, and then uses the recovered key to decode the CosmicPulse payload,"
Microsoft says
.
organisation
EDR
Additionally, using an endpoint detection and response (EDR) solutions in block mode should prevent infections by blocking malicious artifacts even if they are not caught by the antivirus agent.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
victims
100
Organizations
Click for context!
The company says that since the beginning of the year, it has observed at least 13 distinct large-scale phishing campaigns impacting more than 100 organizations, primarily in the United States and the United Kingdom.
Metrics
infrastructure
Windows
Affected Product
Network Configuration Manager:
prepares Windows’ WebDAV functionality so remote web resources can be accessed through file-style paths.
Intelligence Sources
BleepingComputer
2026-09-30
Russian state hackers use new RedFlick technique to push malware
BleepingComputer
Mastodon BleepingComputer
2026-09-30
The Russian state actor Star Blizzard has been using a new m...
Mastodon BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T14:42
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
RedFlick
entity
4x
target region
Target Country
Russian Federation
country
3x
timeline
Temporal Reference
2026
date
2x
tactic
MITRE ATT&CK Technique
T1218.002 - Control Panel
technique
Contextual Telemetry
Context Block
9 METRICS
source region
Origin Country
Russian Federation
country
threat actor
APT Group
Star Blizzard
actor
tactic
Cyber Operation Type
Phishing
tactic
general metric
Distinct Scale Phishing Campaigns
13
distinct scale phishing campaigns
victims
Organizations
100
organizations
industry
Targeted Sector
Health
sector
infrastructure
Affected Product
Windows
software
general metric
Bit Package
4
bit package
general metric
Bit
64
bit
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.