Russian state hackers use new RedFlick technique to push malware
Key Points:
- Russian state actor Star Blizzard has adopted a new malware delivery tactic called "RedFlick" to deploy its CosmicPulse backdoor, automating attacks and reducing victim interaction compared to previous methods.
- RedFlick uses phishing emails with password-protected archives containing virtual disk files and disguised shortcuts that trigger hidden commands to install malware via scheduled tasks with distinct roles, aiding evasion of detection.
- The infection chain includes a downloader called NOROBOT and BAITSWITCH, which fetches and executes the CosmicPulse backdoor capable of running attacker-supplied Python code to steal data or execute files.
- Since early 2026, Microsoft has observed at least 13 large-scale RedFlick phishing campaigns targeting over 100 organizations, mainly in the US and UK, focusing on Ukrainian affiliates, NGOs, governments, and financial institutions supporting Ukraine.
- Microsoft advises organizations to adopt phishing-resistant authentication, Conditional Access policies, email protection, verification of suspicious messages, and endpoint detection and response (EDR) solutions to mitigate these attacks.