Skip to content
Tech News
← Back to articles

Star Blizzard debuts RedFlick delivery method to install CosmicPulse backdoor

read original get YubiKey 5 Series Security Key → more articles
GoKawiil Brief

Microsoft researchers say the Russian state-linked group Star Blizzard is using a new technique called RedFlick to deploy its CosmicPulse backdoor. The chain starts with phishing emails leading victims to open a VHDX virtual disk containing a disguised LNK file, which triggers hidden commands, a decoy PDF, and an MSI installer that sets up three scheduled tasks to reconnoiter the system and fetch further payloads, including a downloader called NOROBOT/BAITSWITCH that ultimately installs CosmicPulse.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The layered, multi-stage delivery chain suggests Star Blizzard is prioritizing automation and detection evasion over previous methods, splitting malicious functions across separate scheduled tasks so each stage appears more benign in isolation. This could make identifying and blocking the group's campaigns harder for defenders, even though the underlying malware family, CosmicPulse, remains consistent with the group's known toolset.

Key Takeaways
Worth a Look

YubiKey 5 Series Security Key — With state-backed phishing crews like Star Blizzard constantly refining malware delivery, hardware-based multi-factor authentication is one of the strongest defenses against credential theft and account takeover. A YubiKey adds a physical layer of security that phishing emails and malicious attachments simply can't bypass. It's a practical step for anyone wanting to harden their accounts against exactly this kind of targeted attack.

See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-30

Published there as: “Russian state hackers use new RedFlick technique to push malware”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.