Cybersecurity

Russian State Hackers Use New RedFlick Technique to Push Malware

The landscape of advanced persistent threats underwent a significant evolution as security researchers uncovered a novel malware deployment tactic employed by the Russian state-sponsored threat group known as Star Blizzard. The operation utilizes a method dubbed "RedFlick" to seamlessly distribute the group’s signature CosmicPulse backdoor while minimizing the need for manual victim interaction. While the core cybersecurity concepts behind the delivery approach are familiar, the orchestration represents a sophisticated step forward in automating nation-state cyber espionage operations.

Disclosed by threat intelligence analysts, the campaign reflects a concerted effort by Star Blizzard to streamline its payload distribution and expand the scale of its phishing infrastructure. The group, which has maintained an active presence in the global threat landscape for nearly a decade, continues to refine its techniques to bypass modern perimeter defenses. By lowering the threshold of user engagement required to execute a payload, the group has successfully scaled its operations against high-profile targets across multiple Western and allied nations.

Anatomy of the RedFlick Attack Chain

The RedFlick infection chain begins with traditional, highly targeted spear-phishing communications. Typically, targets receive an initial introductory message designed to establish a dialogue or build social engineering rapport, followed closely by a secondary communication containing a password-protected ZIP or RAR archive.

Contained within these compressed archives is a Virtual Hard Disk (VHDX) file housing a Windows shortcut (.LNK) file meticulously disguised as a standard PDF document. When an unsuspecting user attempts to open the file, the shortcut initiates a background command executed via a hidden console window. Simultaneously, a decoy PDF document is displayed to the user to maintain the illusion of a normal file-opening event.

Russian state hackers use new RedFlick technique to push malware

The background commands execute a multistep retrieval process, downloading and executing an MSI installer. This installer strategically establishes three distinct scheduled tasks on the compromised host. Each task is configured with a specific operational purpose, posing as legitimate system maintenance or telemetry components. By fragmenting the execution process across multiple scheduled tasks, the threat actors effectively obscure malicious activity and evade signature-based detection mechanisms at various stages of the compromise lifecycle.

Following the establishment persistence via the scheduled tasks, the chain deploys a next-stage downloader known variously as NOROBOT or BAITSWITCH. Delivered in the form of a Control Panel applet (.cpl file), this component is tasked with fetching and executing the ultimate payload: the CosmicPulse backdoor.

According to technical analysis from Microsoft, the BAITSWITCH downloader retrieves two separate ZIP archives. One of these archives contains a legitimate 64-bit Python 3.8 runtime package alongside a custom Python script that functions as a bootstrapper for the backdoor. The bootstrapper reads an encrypted key stored within the Windows registry, decrypts it using an embedded key processed via AES-ECB mode, and subsequently decodes the primary CosmicPulse payload into memory.

Once fully initialized, CosmicPulse grants the operators robust post-exploitation capabilities. Consistent with findings originally detailed by Google’s threat intelligence division, the backdoor enables the execution of arbitrary Python scripts supplied directly by the attacker. This flexibility allows the operators to dynamically download and run supplementary modules, exfiltrate sensitive files, or harvest documents from the infected network environment.

See also  Sanctioned Crypto Exchange Grinex Halts Operations After Alleged $13.74 Million Hack, Blames Western Intelligence Amidst Sanctions Evasion Controversy

Evolution of Star Blizzard Tactics and Historical Context

The deployment of RedFlick marks the latest chapter in a long-standing pattern of innovation by Star Blizzard, a group also tracked by various researchers under names such as Callisto, Seaborgium, and ColdRiver. Active since at least 2017, the organization has historically focused on credential harvesting and intelligence collection targeting diplomats, military officials, government personnel, and non-governmental organizations.

Russian state hackers use new RedFlick technique to push malware

Over the years, the group has systematically diversified its payload delivery mechanisms. Previous campaigns have experimented with innovative delivery routes, including the abuse of messaging platforms like WhatsApp to target high-value diplomats, as well as the adoption of "ClickFix" social engineering frameworks. ClickFix attacks traditionally relied on convincing victims to execute complex manual commands—often masquerading as browser error fixes—to complete an installation.

In contrast, the RedFlick technique represents a notable operational pivot. While ClickFix demanded active, multi-step manual intervention from the target, RedFlick automates the execution chain heavily. The victim only needs to open the initial malicious shortcut file within the VHDX container, after which the automation takes over. This reduction in required user friction lowers the risk of user hesitation or suspicion derailing the attack.

Scale and Scope of the 2026 Campaigns

Telemetry data compiled by Microsoft highlights the industrial scale of Star Blizzard’s operations. Since the beginning of the year, researchers have tracked at least 13 distinct, large-scale phishing campaigns orchestrated by the group. These efforts have successfully targeted more than 100 prominent organizations worldwide, with a heavy concentration of victims located in the United States and the United Kingdom.

The geopolitical motivations underpinning these campaigns remain clear. The RedFlick operations have systematically targeted Ukrainian individuals, civil servants, and state institutions. Furthermore, the targeting matrix extends broadly to international non-governmental organizations (NGOs), political think tanks, government agencies, and financial institutions that have provided political, logistical, or financial support to Ukraine amid the ongoing conflict.

Despite their evolving technical sophistication and the integration of novel delivery mechanisms like VHDX containers and Python-based bootstrappers, Star Blizzard’s foundational operational security habits exhibit consistent patterns. The group continues to rely heavily on free, consumer-grade email providers to initiate phishing correspondence and routinely engages in elaborate impersonation routines, posing as trusted contacts, journalists, or academic peers to establish initial trust.

Russian state hackers use new RedFlick technique to push malware

Official Responses and Industry Disruption

The persistent threat posed by Star Blizzard has prompted coordinated responses from both private-sector technology firms and law enforcement agencies. Prior enforcement actions have included coordinated legal and technical takedowns, such as actions by Microsoft and the United States Department of Justice to seize domains utilized by the threat actors for spear-phishing operations. Despite these disruptions, the group has routinely demonstrated resilience, swiftly pivoting to new infrastructure and adapting its delivery tooling.

See also  Critical Security Flaw in Zimbra Collaboration Suite Exploited by Threat Actors for Data Exfiltration and Remote Access

Security researchers and intelligence agencies emphasize that traditional static defenses are often insufficient to counter the modular nature of campaigns utilizing backdoors like CosmicPulse. Because the final payload is decoded dynamically in memory using legitimate interpreters like Python, file-based antivirus signatures frequently fail to catch the threat during its initial stages.

Mitigation Strategies and Recommendations for Enterprise Defense

In light of the findings surrounding the RedFlick technique and the CosmicPulse backdoor, cybersecurity authorities and enterprise defense teams have issued comprehensive guidance aimed at hardening organizational posture against sophisticated state-sponsored phishing and malware campaigns.

  1. Phishing-Resistant Authentication: Organizations are strongly urged to migrate away from legacy credential mechanisms and implement phishing-resistant multi-factor authentication (MFA), such as FIDO2-compliant security keys or hardware tokens, which cannot be intercepted by real-time adversary-in-the-middle phishing frameworks.

    Russian state hackers use new RedFlick technique to push malware
  2. Endpoint Detection and Response (EDR) Configuration: Security teams should deploy robust EDR solutions configured in aggressive block modes. By enforcing preventative controls at the endpoint, EDR agents can identify and terminate anomalous behavioral patterns—such as hidden window command executions, unauthorized MSI installations, or suspicious scheduled task creation—even if the initial artifact bypasses signature-based antivirus scanning.

  3. Restricting Virtual Disk Mounts and Script Execution: Network administrators should evaluate group policy controls to restrict or monitor the automatic mounting of VHDX and ISO container files, particularly when delivered via external or untrusted sources. Additionally, enforcing strict execution policies for script interpreters and limiting the deployment of unauthorized runtime environments like Python can drastically reduce the attack surface.

  4. Out-of-Band Verification: Personnel operating within targeted sectors, including government agencies, defense contractors, and policy think tanks, must be trained to verify unexpected communications via independent, trusted communication channels rather than replying directly to suspicious messages.

As nation-state actors continue to refine their automation capabilities and lower the barriers to successful exploitation, the discovery of the RedFlick technique underscores the critical necessity for proactive, behavior-based defense models across both public and private sector infrastructures.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.