HomeCyber BalkansRedFlick Utilizes Scheduled Tasks and Password-Protected Archives for CosmicPulse Backdoor Deployment

RedFlick Utilizes Scheduled Tasks and Password-Protected Archives for CosmicPulse Backdoor Deployment

Published on

spot_img

Star Blizzard Expands Cyberespionage Operations in 2026: A Deep Dive into RedFlick Tactics

In 2026, the Russian state-linked threat actor, identified as Star Blizzard, has significantly escalated its cyberespionage activities, utilizing an advanced phishing and malware-delivery technique now known as RedFlick. This heightened level of cyber activity has raised alarms among cybersecurity experts and organizations worldwide.

According to a report from Microsoft Threat Intelligence, the group is believed to be affiliated with the Federal Security Service (FSB) of Russia, specifically the Center 18 division. Between January and August 2026, Star Blizzard successfully conducted a minimum of 13 phishing campaigns. The incidents have predominantly targeted over 100 organizations, with a notable concentration in both the United States and the United Kingdom. Among the affected entities are Ukrainian institutions, various governments, non-governmental organizations (NGOs), think tanks, research organizations, diplomatic personnel, media outlets, and financial institutions—all of which are associated with support initiatives for Ukraine.

Historically, Star Blizzard has utilized sharply focused spear-phishing campaigns, often masquerading as messages from political figures, academic professionals, or diplomatic contacts. However, in 2026, there has been a discernible shift in strategy. Rather than sticking to a narrow target profile, the threat actor broadened its approach by dispatching tens to hundreds of emails per campaign. This tactic serves to identify recipients willing to engage before malware is delivered.

The lures employed in these phishing attempts frequently impersonate invitations to exclusive policy discussions, international conferences, financial events, and forums related to Ukraine. Some phishing emails have been crafted to appear as though they originated from trusted internal contacts or reputable organizations familiar to the intended recipients.

A significant operational change in Star Blizzard’s tactics involves leveraging email accounts established on compromised websites, particularly those hosted on cPanel and WordPress platforms. Microsoft has expressed high confidence that the threat actor compromised these websites in order to create and manage sender accounts, thereby enhancing the authenticity of the phishing messages and reducing reliance on free email services traditionally used in cyberattacks.

The malicious RedFlick operation first takes shape when a target responds to a phishing email that does not contain any attachments. Following this initial exchange, Star Blizzard sends a follow-up message that includes a password-protected ZIP or RAR archive, with the password discreetly provided as an embedded image within the email itself. This technique complicates automated email inspections as many security products struggle to scan the encrypted contents before they reach the endpoint.

The subsequent follow-up email arrives within an ostensibly legitimate email conversation, increasing the likelihood that the recipient will view the attachment as a necessary document. Researchers from Fieldeffect have observed that RedFlick employs various methods, including password-protected archives, scheduled tasks, WebDAV, and disguised Windows components, to install a backdoor known as CosmicPulse on targeted systems.

During earlier campaigns in 2026, ZIP archives were used that contained VHDX virtual disk images. These images included a malicious Windows shortcut disguised as a PDF document, a hidden BAT script, and a decoy PDF file. When victims launched the shortcut, the script would activate the decoy while leveraging legitimate Windows binaries and SSH functionalities to download and execute a remote MSI installer.

Starting in April, the tactics evolved further. Microsoft noted that the MSI installers were no longer limited to creating a single scheduled task. Observations indicated that they began generating three separate scheduled tasks that masqueraded as benign Windows or network-management components: Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.

The first scheduled task collects basic host data, such as the computer or network name and the user’s name, transmitting this information back to the command-and-control infrastructure. This task can also invoke attacker-controlled dynamic-link libraries (DLLs) remotely. The second task facilitates the WebClient functionality needed to access WebDAV paths, allowing Windows to retrieve remote resources over HTTP or HTTPS as though they were standard network shares. The third task enables a remote Control Panel applet, or CPL file, that functions as a CosmicPulse downloader, facilitating the installation of a Python environment. This environment encrypts the final payload and launches the CosmicPulse backdoor.

The malicious software is also referred to publicly as YESROBOT, while its downloader is known as NOROBOT or BAITSWITCH. In July 2026, Star Blizzard introduced a new variation of RedFlick, whereby a password-protected RAR archive was nested inside a ZIP file. This innovative method made use of an LNK file which engaged Windows tools to download a PDF from actor-controlled infrastructure. Unlike past methods, this PDF was imbued with Base64-encoded data, which a PowerShell command could extract and execute to download additional MSI installers.

Given the sophistication involved in these attacks, cybersecurity defenders are urged to scrutinize password-protected archives transmitted after initial email exchanges devoid of attachments—especially cases where passwords are visually embedded in images or where senders assert that an attachment was inadvertently omitted. Endpoint telemetry becomes crucial, as mail-layer controls may have limited visibility into encrypted archives.

In conclusion, Microsoft emphasizes the importance of employing phishing-resistant authentication methods, Conditional Access, Safe Links, Safe Attachments, and robust endpoint detection and response strategies to combat such advanced cyber threats. The alert system should include high-value hunting signals like suspicious behaviors associated with VHDX mounting and unusual PowerShell activity, thereby fortifying defenses against the stealthy maneuvers of threat actors like Star Blizzard.

Source link

Latest articles

UAE Fends Off Iranian Cyberattacks

Gulf Kingdoms Cite Information Sharing and Private Sector Support in Cyber Defense In a world...

AI-Discovered Vulnerabilities More Likely to Enable RCE, According to Google

Rising Vulnerabilities and AI: A 2026 Analysis In a recent significant development, the Google Threat...

The MFA You Have Isn’t What You Think It Is

The Evolving Landscape of Multi-Factor Authentication: Challenges and Solutions For nearly a decade, organizations have...

CyberASAP Marks 10th Anniversary with Unique Event on the Future of Cyber Security Innovation in the UK

In 2026, the Cyber Security Academic Startup Accelerator Programme, widely known as CyberASAP, proudly...

More like this

UAE Fends Off Iranian Cyberattacks

Gulf Kingdoms Cite Information Sharing and Private Sector Support in Cyber Defense In a world...

AI-Discovered Vulnerabilities More Likely to Enable RCE, According to Google

Rising Vulnerabilities and AI: A 2026 Analysis In a recent significant development, the Google Threat...

The MFA You Have Isn’t What You Think It Is

The Evolving Landscape of Multi-Factor Authentication: Challenges and Solutions For nearly a decade, organizations have...