Star Blizzard debuts RedFlick delivery method to install CosmicPulse backdoor
Microsoft researchers say the Russian state-linked group Star Blizzard is using a new technique called RedFlick to deploy its CosmicPulse backdoor. The chain starts with phishing emails leading victims to open a VHDX virtual disk containing a disguised LNK file, which triggers hidden commands, a decoy PDF, and an MSI installer that sets up three scheduled tasks to reconnoiter the system and fetch further payloads, including a downloader called NOROBOT/BAITSWITCH that ultimately installs CosmicPulse.