Microsoft researchers observed a new technique that the group calls RedFlick, used by the Russian entity Star Blizzard to install the CosmicPulse backdoor on victims’ devices. The technique is not itself a new offensive technology, but it changes how the malware is delivered by automating stages of the infection and reducing the number of actions required from the user.
Microsoft said that Star Blizzard expanded its phishing operations during 2026, and that since the beginning of the year it had observed at least 13 large-scale phishing campaigns affecting more than 100 organizations, most of them in the United States and the United Kingdom. The targets included Ukrainian individuals and institutions, as well as nongovernmental organizations, research centers, governments, and financial institutions that supported Ukraine politically or financially.
How Does the RedFlick Chain Work?
The campaign begins with a phishing message, such as an invitation, followed by a second message containing a password-protected ZIP or RAR archive. The archive contains a VHDX virtual disk with an LNK file inside disguised as a PDF file.
When the shortcut is opened, the file executes a command in a hidden window while simultaneously displaying a fake PDF file to distract the victim. It then downloads and runs an MSI installer, which creates three scheduled tasks with names that appear to be legitimate maintenance components:
- Internet Quality Test Connection: Sends the computer or network name and the username to the attackers, and can remotely execute a DLL.
- Network Configuration Manager: Prepares the WebDAV function in Windows to access remote web resources through paths resembling file paths.
- System Health Monitor: Uses control.exe to run a remotely hosted subsequent payload.
Distributing roles across several scheduled tasks helps the attackers conceal different stages of the operation. The NOROBOT and BAITSWITCH downloaders are then delivered as Control Panel application (.cpl) files, with the aim of retrieving and running the CosmicPulse backdoor.
What Changes in Practice?
BAITSWITCH downloads two archives, one of which contains a 64-bit Python 3.8 package and a Python file that serves as a bootstrapper for the backdoor. According to Microsoft, this file reads an encrypted key from the Windows Registry, decrypts it using an embedded key and AES-ECB mode, and then uses the recovered key to decrypt the CosmicPulse payload.
According to Microsoft, the backdoor’s capabilities remained similar to those described in Google’s October 2025 report, including executing attacker-specified Python code to download and run files or retrieve documents from infected systems.
In practice, with RedFlick, all the victim has to do is open the malicious shortcut for an automated infection chain to begin. This relies less on manual interaction than previous ClickFix campaigns, which required victims to perform several steps.
Defensive Implications and Detection Limitations
Star Blizzard continues to impersonate trusted entities or contacts and also relies on free email services to send phishing messages, despite changing its methods and procedures. Microsoft recommends using phishing-resistant authentication, Conditional Access policies, email protection, and independent verification of suspicious messages through previously known contact details.
The company also notes that running endpoint detection and response (EDR) solutions in blocking mode can prevent infection by blocking malicious files, even if antivirus software does not detect them. The campaign shows that relying solely on user awareness is insufficient when a single message and the opening of a shortcut can launch a multistage chain.