Microsoft Tracks RedFlick Phishing Tactic Used by Star Blizzard to Deliver CosmicPulse
Microsoft researchers say a Russia-linked group is using a new delivery chain called RedFlick to install the CosmicPulse backdoor through phishing emails and a largely automated infection process.

BleepingComputer reports that Microsoft researchers have described a new malware-delivery method called RedFlick, used by the Russia-linked threat actor Star Blizzard to install its CosmicPulse backdoor. The technique is not a new type of cyberattack, but Microsoft says it represents a fresh approach for the group and allows it to automate more of the infection process while asking less of the victim.
Microsoft says Star Blizzard has expanded its phishing operations and made malware delivery more efficient in 2026. The actor has been active since 2017 and has a history of testing new payload routes, including ClickFix and WhatsApp, as well as introducing new malware families.
According to the report, RedFlick attacks begin with a phishing email, such as an invitation. A follow-up message carries a password-protected ZIP or RAR file. Inside is a VHDX virtual disk containing an LNK shortcut that appears to be a PDF. When the target opens it, a command runs in a hidden window while a decoy PDF is displayed. The command downloads and executes an MSI installer. That installer creates three scheduled tasks made to resemble ordinary maintenance components. Microsoft says the separate tasks, each with a different role, help the attacker avoid detection at different stages.
The next stage uses NOROBOT and BAITSWITCH, described as downloaders delivered as a Control Panel applet (.cpl). Their purpose is to fetch and run CosmicPulse. BAITSWITCH downloads two ZIP archives; one contains Python 3.8 64-bit and a Python file that acts as a bootstrapper for the backdoor. Microsoft says the bootstrapper retrieves an encrypted key from the registry, recovers it with an embedded AES-ECB key, and then decodes the CosmicPulse payload.
Microsoft notes that CosmicPulse's capabilities in these attacks match those described in a Google report from October 2025. Those capabilities include executing attacker-supplied Python code to download and run files or to retrieve documents from infected systems.
RedFlick reduces the victim's role compared with earlier ClickFix attacks. In ClickFix, the source says Star Blizzard required victims to take multiple manual actions. With RedFlick, opening the malicious shortcut is enough to start an automated infection chain.
Microsoft says it has observed at least 13 distinct large-scale phishing campaigns since the beginning of the year, affecting more than 100 organizations, mainly in the United States and the United Kingdom. The RedFlick campaigns have targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially.
Star Blizzard continues to impersonate trusted contacts or organizations and still depends on free email providers to send phishing messages, according to the researchers.
Microsoft's advice includes phishing-resistant authentication, Conditional Access policies, email protection, and independently confirming suspicious messages through known contact details. It also recommends endpoint detection and response tools in block mode, which can block malicious artifacts even if antivirus does not catch them. The source material does not describe a software patch for RedFlick; the reported response is a mix of prevention, detection, and verification.
Sources and further reading
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

