Star Blizzard Refines Phishing Delivery
Microsoft says the Russian state actor's RedFlick chain cuts victim interaction down to a single click while scaling phishing across 100+ targets.
Opening a file that looks like a PDF should not be enough to hand an attacker a foothold inside a corporate network. According to Microsoft, Russian state actor Star Blizzard has built a delivery chain that gets close to exactly that — and has used it in at least 13 large-scale phishing campaigns since the start of the year.
The technique is called RedFlick, and Microsoft researchers describe it as a new malware installation tactic for the group rather than a new class of vulnerability. The distinction matters: no software flaw is being exploited here. The chain leans on the victim's own actions, compressed into as few steps as possible, to deploy the group's signature CosmicPulse backdoor.
Who Star Blizzard Targets
Star Blizzard, which Microsoft says has been active since 2017, has a track record of experimenting with delivery methods. Microsoft points to prior use of ClickFix lures and WhatsApp as channels for reaching targets, alongside a steady output of new malware families.
The targeting profile in the RedFlick campaigns follows that pattern. According to the researchers, the campaigns have hit Ukrainian individuals and institutions, along with international NGOs, think tanks, governments, and financial institutions that have backed Ukraine politically or financially. Microsoft says it has observed at least 13 distinct large-scale phishing campaigns affecting more than 100 organizations, primarily in the United States and the United Kingdom.
Despite the shift in tactics, techniques, and procedures, the group's social engineering has stayed consistent. Microsoft says Star Blizzard continues to impersonate trusted contacts or organizations and still relies on free email providers to deliver its phishing messages — a low-cost approach that keeps the sender infrastructure disposable.
How the RedFlick Chain Starts
The attack opens with a phishing email, often framed as an invitation. A second message follows containing a password-protected ZIP or RAR archive — password protection that keeps automated email scanners from inspecting the contents.
Inside the archive sits a VHDX virtual disk. Within that disk is an LNK file disguised as a PDF. When the victim opens it, the shortcut launches a command in a hidden window while a decoy PDF is displayed on screen, so the visible result matches what the target expected to see.
From there, the commands download and run an MSI installer. That installer sets up the persistence layer that Microsoft's analysis focuses on: three scheduled tasks, each named to look like a routine maintenance component of Windows.
Three Tasks, Three Jobs
The scheduled tasks are not redundant copies of one another. Microsoft describes each as having a distinct role in the chain:
- Internet Quality Test Connection — sends the computer or network name and username to the attackers and can execute a remote DLL.
- Network Configuration Manager — prepares Windows' WebDAV functionality so remote web resources can be accessed through file-style paths.
- System Health Monitor — uses control.exe to execute a remotely hosted next-stage payload.
Splitting the work across multiple tasks with separate functions helps the attacker evade detection at different stages of the intrusion. A security tool that flags one behavior may see nothing unusual in the others.
From Scheduled Task to Backdoor
The next-stage payload is a downloader Microsoft identifies as NOROBOT and BAITSWITCH, delivered as a Control Panel applet (.cpl). Its job is to fetch and execute CosmicPulse.
BAITSWITCH pulls down two ZIP archives. One contains the Python 3.8 64-bit package and a Python file that acts as a bootstrapper for CosmicPulse. The bootstrapper does not carry the payload in the clear.
"The bootstrapper reads the encrypted key from the registry, recovers it using an embedded key in AES-ECB mode, and then uses the recovered key to decode the CosmicPulse payload," Microsoft says.
— Microsoft researchers, in the company's analysis of the RedFlick infection chain
Microsoft adds that the backdoor's capabilities in the observed attacks match what was described in an October 2025 report from Google. That includes executing attacker-supplied Python code to download and run files, or to retrieve documents from infected systems.
Why One Click Is the Point
The practical difference between RedFlick and the group's earlier ClickFix activity comes down to victim effort. Microsoft notes that RedFlick only requires the target to open the malicious shortcut file to trigger an automated infection chain. In the ClickFix attacks, Star Blizzard needed victims to perform multiple manual actions.
Fewer steps means fewer chances for a target to get suspicious and stop. It also means less reliance on a victim following instructions correctly — a frequent point of failure in social engineering campaigns that depend on the target pasting commands or navigating menus.
The VHDX container and the PDF-disguised LNK serve the same goal from the other direction, hiding the payload from casual inspection. A file that opens to show a document looks harmless to most users, and the password-protected archive upstream keeps the content out of reach of gateway scanners.
What Microsoft Recommends
Microsoft's guidance for defending against the campaign centers on hardening identity and email, then backing that up with endpoint controls:
- Use phishing-resistant authentication so stolen credentials alone are not enough to sign in.
- Apply Conditional Access policies to constrain how and from where accounts can be used.
- Keep email protection in place to catch malicious messages before they reach inboxes.
- Independently verify suspicious messages through established contact details rather than replying to the message itself.
The company also points to endpoint detection and response (EDR) solutions running in block mode. Microsoft says this should prevent infections by blocking malicious artifacts even when they are not caught by the antivirus agent — a layered approach aimed at the point in the chain where the scheduled tasks and the MSI installer appear.
The Numbers Behind the Campaign
Microsoft's figures give a sense of scale for the activity it has tracked this year:
- 13 distinct large-scale phishing campaigns observed since the beginning of the year.
- 100+ organizations impacted by those campaigns.
- Primary victim geographies: the United States and the United Kingdom.
- Targeting also includes Ukrainian individuals and institutions, plus NGOs, think tanks, governments, and financial institutions that have supported Ukraine.
- Star Blizzard activity documented as far back as 2017.
- Prior CosmicPulse capability reporting dates to a Google report from October 2025.
The Python component in the chain is pinned to version 3.8, 64-bit, and the downloader arrives as a .cpl Control Panel applet. The key recovery step uses AES-ECB mode with an embedded key, with the encrypted key retrieved from the registry.
The Takeaway for Defenders
Star Blizzard's RedFlick chain is a reminder that delivery mechanics, not exploits, often decide whether an intrusion succeeds. The group did not need a zero-day to reach CosmicPulse. It needed a target to open one file — and it built the surrounding chain so that everything after that click happens without the victim's involvement.
Organizations that fit the targeting profile, particularly those with ties to Ukraine or those operating in government, NGO, think tank, and financial sectors, have reason to treat invitation-style phishing with more suspicion than usual. The combination of a password-protected archive, a VHDX disk, and a shortcut wearing a PDF icon is unusual enough to warrant scrutiny at the mail gateway and on the endpoint alike.
The scheduled-task names are worth noting for detection teams. Names like Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor blend into the background noise of a Windows machine, which is exactly why the attacker chose them. Verifying what created a scheduled task, not just what it is called, is the harder and more useful question.
Microsoft's report provides the technical analysis of the infection chain and the components involved. For defenders who want to check exposure, the practical steps are the ones the company laid out: phishing-resistant authentication, Conditional Access, email protection, independent verification of suspicious messages, and EDR in block mode.
Sources
- BleepingComputer Original source
- active since 2017 Also reporting
- ClickFix Also reporting
- WhatsApp Also reporting
- new malware families Also reporting
Continue Reading
NetScaler Flaw Weaponized for Deep Access
LevelBlue says attackers exploited a critical NetScaler bug to plant web shells, create superuser accounts, and exfiltrate configuration data.
Zimbra Bug Exploited for Mailbox Theft
Microsoft says attackers chained a patched Zimbra command-injection flaw into web shells, credential theft and cloud exfiltration.
Dual RMM Phishing Attack Evades Defenses
Microsoft says phishing emails hid a legitimate MSP360 installer behind meeting and PDF lures, then used it to install ScreenConnect as a redundant remote-access channel.