Russia's Star Blizzard deploys new RedFlick infection chain against 100+ organisations

· CyberSecurity

TLDR

  • Microsoft disclosed a new infection technique, RedFlick, used by Russian state actor Star Blizzard in at least 13 large-scale phishing campaigns since January, hitting more than 100 organisations mostly in the US and UK.
  • Victims receive fake event invitations impersonating think tanks and NGOs; replying triggers a password-protected archive containing a disguised shortcut file that needs only one click to start an automated infection chain.
  • The chain installs three disguised scheduled tasks that ultimately fetch a Python-based backdoor called CosmicPulse.
  • Targets also include Ukrainian individuals and institutions, plus NGOs, governments and financial institutions supporting Ukraine.

Microsoft disclosed a new malware delivery technique called RedFlick used by Star Blizzard, a Russian state hacking group that security agencies have attributed to Center 18 of Russia's Federal Security Service (FSB).2 Unlike the group's 2025 ClickFix technique, which required victims to manually complete several steps, RedFlick needs only a single click: the victim opens a disguised shortcut file to trigger a fully automated infection chain.1

The campaign uses fake event invitations impersonating well-known think tanks and NGOs, such as Chatham House and the Atlantic Council, as social-engineering bait.3 Targets who reply are sent a password-protected archive containing a virtual disk image with a shortcut file disguised as a PDF; opening it runs an MSI installer that creates three disguised scheduled tasks named "Internet Quality Test Connection," "Network Configuration Manager" and "System Health Monitor."1 These tasks exfiltrate the victim's computer and network name, enable WebDAV access to remote resources, and ultimately launch a downloader, previously tracked as NOROBOT or BAITSWITCH, disguised as a Windows Control Panel applet.1 The downloader fetches a Python bootstrapper that decrypts and installs the final payload: CosmicPulse, a Python-based backdoor whose capabilities Google first detailed in October 2025.2

Microsoft counted at least 13 distinct large-scale phishing campaigns this year affecting more than 100 organisations, mostly in the US and UK, alongside Ukrainian individuals and institutions and other NGOs, think tanks, governments and financial institutions supporting Ukraine.1 Since March, the group has shifted from free email providers toward hacked WordPress and cPanel email accounts to send its lures.2 Microsoft and the Digital Security Lab Ukraine separately found overlapping indicators, including the IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com, which remained active when Microsoft published its findings.2 Microsoft recommends phishing-resistant authentication, Conditional Access policies and endpoint detection in block mode to counter the technique.1

Why it matters: RedFlick strips out the extra steps that made Star Blizzard's prior ClickFix lures easier to catch, so a single click on a convincing fake invite is now enough to compromise an NGO, government office or financial institution supporting Ukraine, raising the odds that a brief lapse in user judgement turns into a full backdoor installation.

Sources

  1. Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor (The Hacker News)
  2. Russian state hackers use new RedFlick technique to push malware (BleepingComputer)
  3. Russian APT Star Blizzard Uses 'RedFlick' Infection Chain in Recent Attacks (SecurityWeek)