Russian state hackers utilize brand-new RedFlick strategy to press malware

Red carpet

The Russian state star Star Blizzard has actually been utilizing a brand-new malware setup technique called”RedFlick”to release its signature CosmicPulse backdoor.

The technique is not a brand-new cybersecurity method, it is a brand-new shipment technique for the hazard star, permitting it to even more automate attacks and decrease victim interaction.

Microsoft scientists state that Star Blizzard broadened its phishing operations and structured malware shipment in 2026.

Star Blizzard, active given that 2017, is understood for checking out brand-new payload shipment opportunities like ClickFix or WhatsApp, and for constantly establishing and releasing brand-new malware households.

New RedFlick strategy

RedFlick attacks start with a phishing e-mail, such as an invite, followed by a 2nd message consisting of a password-protected ZIP or RAR archive.

The archive includes a VHDX virtual disk with an LNK file camouflaged as a PDF. When the file is opened, it releases a command in a concealed window while showing a decoy PDF to the victim.

VHDX-based attack chain
Source: Microsoft

The commands download and run an MSI installer that develops 3 set up jobs impersonating genuine upkeep parts, each with a particular function:

  1. Web Quality Test Connection: sends out the computer/network name and username to the enemies and can carry out a remote DLL.
  2. Network Configuration Manager:prepares Windows’ WebDAV performance so remote web resources can be accessed through file-style courses.
  3. System Health Monitor:usages control.exe to perform a from another location hosted next-stage payload.

Considering that the brand-new approach utilizes numerous arranged jobs with unique functions, it assists the enemy avert detection at various phases of the attack.

The next-stage payload is a downloader called NOROBOT and BAITSWITCH, provided in the type of a Control Panel applet (. cpl). Its function is to bring and perform the CosmicPulse backdoor.

RedFlick arranged jobs
Source: Microsoft

BAITSWITCH downloads 2 ZIP archives, among them including the Python 3.8 64-bit plan and a Python file functioning as a bootstrapper for CosmicPulse.

“The bootstrapper reads the encrypted key from the registry, recovers it using an embedded key in AES-ECB mode, and then uses the recovered key to decode the CosmicPulse payload,” Microsoft states

. Attack chain summary
Source: Microsoft

Microsoft keeps in mind that the backdoor’s abilities in the observed attacks stay the like explained in a report from Google in October 2025, consisting of the execution of attacker-supplied Python code to download and run files or recover files from contaminated systems.

From a useful viewpoint, RedFlick just needs the victim to open the harmful faster way file to activate an automatic infection chain, whereas in the ClickFix attacks, Star Blizzard needed victims to take several manual actions.

Microsoft’s report offers technical analysis of the infection chain and the parts utilized in the attacks.

The business states that because the start of the year, it has actually observed a minimum of 13 unique massive phishing projects affecting more than 100 companies, mainly in the United States and the United Kingdom.

“The RedFlick projects have actually targeted Ukrainian people and organizations, in addition to global NGOs, believe tanks, federal governments, and banks that have actually supported Ukraine politically or economically,” the scientists state.

Regardless of altering its strategies, strategies, and treatments, StarBlizzard continues to target users by impersonating relied on contacts or companies, and still counts on totally free e-mail suppliers to provide phishing messages.

Microsoft advises that business utilize phishing-resistant authentication, Conditional Access policies, e-mail security, and individually confirm suspicious messages through communicated information.

In addition, utilizing an endpoint detection and reaction (EDR) services in block mode ought to avoid infections by obstructing destructive artifacts even if they are not captured by the antivirus representative.

red carpet article image

Red carpet

Develop your security plan for AI-powered attacks

Sign Up With Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital top on what AI-speed attacks alter, what protectors must stop doing, and how to confirm, choose, repair, and re-validate at maker speed.

Conserve your seat


Discover more from PMN S.P.O.R.T.S - A PRIME MEDIA NETWORK BRAND

Subscribe to get the latest posts sent to your email.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here