Russian state-linked risk actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery approach tracked by Microsoft as RedFlick.
Microsoft Menace Intelligence reported that the group, which CISA attributes to Russia’s Federal Safety Service (FSB) Middle 18, carried out at the least 13 phishing campaigns between January and August 2026.
The exercise affected greater than 100 organizations, primarily in america and United Kingdom, with targets together with Ukrainian establishments, governments, NGOs, assume tanks, analysis organizations, diplomatic employees, media entities, and monetary establishments related to assist for Ukraine.
Star Blizzard traditionally relied on tightly focused spear-phishing campaigns, usually impersonating political figures, teachers, or diplomatic contacts.
In 2026, nonetheless, the actor broadened its preliminary outreach, sending tens to tons of of emails per marketing campaign to determine recipients prepared to have interaction earlier than delivering malware.
The lures generally impersonated invites to closed-door coverage discussions, worldwide conferences, monetary occasions, and Ukraine-related boards.
In some instances, phishing emails appeared to originate from inner contacts or respected organizations identified to the supposed goal.
A key operational change concerned the usage of electronic mail accounts created on compromised web sites, together with websites hosted on cPanel and WordPress infrastructure.
Microsoft assessed with excessive confidence that Star Blizzard compromised these web sites to create and function sender accounts, serving to the actor keep away from relying solely on free electronic mail suppliers and rising the credibility of phishing messages.
The RedFlick chain begins solely after a recipient responds to an attachment-free phishing electronic mail.
Star Blizzard then sends a follow-up message containing a password-protected ZIP or RAR archive, whereas offering the password as a picture embedded within the electronic mail.
This supply technique complicates automated electronic mail inspection as a result of safety merchandise could also be unable to scan encrypted archive contents earlier than they attain the endpoint.
RedFlick Backdoor
The follow-up additionally arrives inside an apparently reliable electronic mail dialog, rising the probability {that a} recipient will regard the attachment as an anticipated doc.
Fieldeffect Researchers noticed that, RedFlick makes use of password-protected archives, scheduled duties, WebDAV, and disguised Home windows parts to put in the CosmicPulse backdoor on focused techniques.
Earlier 2026 campaigns used ZIP archives containing VHDX digital disk photos. The VHDX file included a malicious Home windows shortcut, or LNK, disguised as a PDF doc, a hidden BAT script, and a decoy PDF.
When a sufferer launched the shortcut, the script opened the decoy whereas utilizing reliable Home windows binaries and SSH performance to obtain and execute a distant MSI installer.
Starting in April, RedFlick installers moved past making a single scheduled process.
Microsoft noticed MSI installers creating three scheduled duties masquerading as benign Home windows or network-management parts: Web High quality Check Connection, Community Configuration Supervisor, and System Well being Monitor.
The primary process sends primary host information, together with the pc or community title and username, to command-and-control infrastructure. It will possibly additionally invoke attacker-controlled DLLs remotely by way of Control_RunDLL and Shell32.dll.
A second process allows the WebClient performance required to entry WebDAV paths, permitting Home windows to retrieve distant assets over HTTP or HTTPS whereas treating them like community shares.
The third process makes use of management.exe to retrieve and execute a distant Management Panel applet, or CPL file. That part features as a CosmicPulse downloader, putting in a Python surroundings, decrypting the ultimate payload, and launching the CosmicPulse backdoor.
The malware can also be publicly often called YESROBOT, whereas its downloader has been known as NOROBOT or BAITSWITCH.
In July, Star Blizzard launched one other RedFlick variation that nested a password-protected RAR archive inside a ZIP file.
The archive uncovered an LNK file which used conhost.exe and curl to obtain a PDF from actor-controlled infrastructure.
Somewhat than serving solely as a decoy, the PDF hid Base64-encoded information. A PowerShell command searched the downloaded file for a cAB marker, extracted 208 bytes of encoded content material, decoded it, and executed the end result to obtain one other MSI installer.
The installer then tried to create extra scheduled duties and deploy the CPL-based CosmicPulse downloader.
Defenders ought to examine password-protected archives delivered after attachment-free electronic mail exchanges, particularly the place passwords are embedded in photos or senders declare an attachment was beforehand omitted.
Endpoint telemetry is essential as a result of mail-layer controls could have restricted visibility into encrypted archives.
Excessive-value looking indicators embody VHDX mounting, LNK recordsdata masquerading as PDFs, conhost.exe launching curl, suspicious msiexec.exe habits, PowerShell extracting content material from PDFs, ssh.exe executed with PermitLocalCommand, WebDAV exercise, and creation of the three scheduled-task names related to RedFlick.
Microsoft additionally recommends phishing-resistant authentication, Conditional Entry, Secure Hyperlinks, Secure Attachments, endpoint detection and response in block mode, and controls that stop execution of obfuscated scripts.
Lower each SOC alert investigation by 21 min. Energy your SOC with instantaneous IOC context for fast response: Combine TI Lookup in your SOC








