Full Report
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
Analysis Summary
# Threat Actor: Star Blizzard
## Attribution & Identity
* **Actor Identification:** Star Blizzard is a Russian state-sponsored threat actor (associated with the FSB).
* **Aliases:** ColdRiver, SEABORGIUM, Callisto Group, TA446.
* **Known Associations:** Attributed to Russian intelligence services; active since at least 2017.
## Activity Summary
In 2026, Star Blizzard expanded its operations using a new malware delivery tactic dubbed **"RedFlick."** This technique automates the infection chain to reduce required victim interaction. Microsoft observed at least 13 distinct large-scale phishing campaigns in 2026, impacting over 100 organizations.
## Tactics, Techniques & Procedures
* **Phishing/Spear-Phishing:** Uses free email providers to impersonate trusted contacts or organizations.
* **Multi-Stage Delivery:** Employs a two-step email process (initial invitation followed by a password-protected ZIP/RAR archive).
* **Container Files:** Uses VHDX virtual disks to bypass security scanners.
* **Persistence via Scheduled Tasks:** Creates three specific tasks posing as legitimate system components:
* *Internet Quality Test Connection* (Recon/Remote DLL execution)
* *Network Configuration Manager* (WebDAV preparation)
* *System Health Monitor* (Next-stage execution)
* **Living off the Land (LotL):** Utilizes `control.exe` to execute malicious `.cpl` files.
* **Evasion:** Uses encrypted registry keys and AES-ECB mode to decode final payloads.
* **MITRE ATT&CK IDs (Inferred from text):**
* T1566.001 (Phishing: Spearphishing Attachment)
* T1053.005 (Scheduled Task/Job: Scheduled Task)
* T1218.002 (System Binary Proxy Execution: Control Panel)
* T1553.005 (Subvert Trust Controls: Control Panel Items)
## Targeting
* **Sectors:** Governments, International NGOs, Think Tanks, Financial Institutions, and Educational Institutions.
* **Geography:** Primarily the United States, United Kingdom, and Ukraine.
* **Victims:** Over 100 organizations; specifically individuals and institutions supporting Ukraine politically or financially.
## Tools & Infrastructure
* **Malware Families:**
* **CosmicPulse:** Signature Python-based backdoor.
* **NOROBOT / BAITSWITCH:** Downloaders delivered as Control Panel applets (.cpl).
* **SPICA:** Backdoor (referenced historical tool).
* **Infrastructure:**
* Use of WebDAV for remote resource access.
* Use of free email providers (e.g., ProtonMail, Gmail) for delivery.
* **C2/Links:** `https[:]//www[.]bleepingcomputer[.]com` (Contextual source - no specific malicious C2 domains listed in article text).
## Implications
Star Blizzard is successfully evolving from high-interaction social engineering to automated, streamlined infection chains (RedFlick). By diversifying TTPs (VHDX files, multiple scheduled tasks, and CPL applets), the actor is increasing its ability to evade traditional antivirus and EDR detections while maintaining its strategic focus on high-value intelligence related to Ukrainian support.
## Mitigations
* **Authentication:** Implement phishing-resistant multi-factor authentication (MFA).
* **Access Control:** Deploy Conditional Access policies to restrict resource access.
* **Endpoint Security:** Use EDR solutions in "Block Mode" to intercept malicious artifacts.
* **Verification:** Independently verify suspicious communications via out-of-band channels.
* **File Filtering:** Restrict or monitor the mounting of VHDX files and the execution of .cpl files from untrusted sources.