Microsoft researchers report the Russian state actor Star Blizzard has adopted a delivery approach dubbed RedFlick that further automates its CosmicPulse backdoor attacks, requiring the victim only to open a malicious shortcut file. The chain begins with a phishing email, followed by a second message with a password-protected ZIP or RAR containing a VHDX virtual disk whose LNK file is disguised as a PDF; opening it runs a hidden command and displays a decoy PDF. An MSI installer creates three scheduled tasks posing as maintenance components — Internet Quality Test Connection, Network Configuration Manager and System Health Monitor — the last using control.exe to execute a remotely hosted .cpl downloader, NOROBOT or BAITSWITCH, that fetches CosmicPulse, whose payload is AES-ECB-decoded from a registry-stored key. Microsoft says it observed at least 13 distinct large-scale campaigns this year impacting more than 100 organisations, primarily in the United States and United Kingdom, targeting Ukrainian institutions and the NGOs, think tanks, governments and financial institutions that have supported Ukraine.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-02 |
| Source | Microsoft Security Blog |
| Reliability | Tier 1 |