Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
Star Blizzard (SEABORGIUM) RedFlick technique (TL-2026-2787), also tracked as RedFlick, is a high-severity advanced persistent threat campaign, first published 2026-09-29 and last reviewed 2026-09-30. It is attributed to Star Blizzard (Russia) with high confidence, affects Microsoft Windows, maps to 20 MITRE ATT&CK techniques (T1027, T1027.003, T1036.005), and is covered by 9 detection rules and 36 indicators of compromise.
Key facts for TL-2026-2787
- Threat ID
- TL-2026-2787
- Also known as
- RedFlick, CosmicPulse, YESROBOT, NOROBOT, BAITSWITCH
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-09-29
- Last reviewed
- 2026-09-30
- Attribution
- Star Blizzard
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, ngo, think-tank, finance, academia, diplomatic, hospitality, technology
- Target regions
- ukraine, united states of america, united kingdom, Europe
- Detection rules
- 9
- Indicators of compromise
- 36
- Updates
- 2026-09-30 · revalidated 1× · latest source
Malware and tooling in Star Blizzard (SEABORGIUM) RedFlick technique
Malware and tooling: MAYBEROBOT, NOROBOT, YESROBOT
Microsoft Threat Intelligence reports that Russian FSB Centre 18 actor Star Blizzard (SEABORGIUM/COLDRIVER) has shifted from targeted spear-phishing to large-scale phishing and uses the RedFlick technique, in which scheduled tasks deploy backdoors with fewer user interactions than earlier ClickFix chains. Payloads include the Python backdoor CosmicPulse (YESROBOT) and a Control Panel applet (CPL) downloader (NOROBOT/BAITSWITCH); more than 100 organizations were affected, primarily in Ukraine and then the US and UK.
How Star Blizzard (SEABORGIUM) RedFlick technique works
Microsoft Threat Intelligence (2026-09-29) describes how Star Blizzard, a Russian state actor assessed by CISA and partner agencies (AA23-341A) as almost certainly subordinate to FSB Centre 18, evolved during 2026 from manual, targeted spear-phishing to mass-mailing campaigns of tens to hundreds of emails per wave. Lures impersonate legitimate organizations: conference and roundtable invitations (IISS, Chatham House, Atlantic Council-themed, USUBC, MAMA Summit, Future of Liberty/Peace Operations forums), Ukrainian-language tax and fine-payment notices, a Kyiv water-supply outage notice aimed at hotels, and a payment advice note aimed at an international financial organization. From March 2026 onward the actor also created accounts on compromised cPanel/WordPress-hosted sites to send phishing. Targets include Ukrainian individuals, NGOs, think tanks, governments and financial institutions supporting Ukraine; over 100 organizations were affected, primarily in Ukraine and then the US and UK.
After a recipient replies, a follow-up email delivers a password-protected RAR/ZIP archive, with the password shown as an image to evade email filtering. The archive starts the RedFlick chain, which needs a single user interaction. In the January 2026 variant a ZIP holds a VHDX containing an LNK disguised as a PDF and a hidden BAT directory. The LNK launches a hidden conhost.exe and cmd.exe, and the BAT opens a decoy PDF and runs ssh.exe with PermitLocalCommand enabled to download an MSI from attacker infrastructure. The MSI creates a scheduled task that uses control.exe to fetch a CPL downloader (CosmicPulse downloader, aka NOROBOT/BAITSWITCH). In the July 2026 variant a RAR nested in a ZIP holds an LNK that uses conhost.exe and curl to download a PDF. PowerShell locates the magic header 'cAB' in the PDF, extracts 208 bytes of Base64 data, and decodes a command that downloads the MSI, which creates two scheduled tasks. In mid-August 2026 the actor added image-based/steganographic obfuscation.
From April 2026 persistence moved to three coordinated scheduled tasks masquerading as Windows components: 'Internet Quality Test Connection' (beacons a UTF-16 Base64 string containing network/computer name and username to the C2 and runs an attacker DLL via Shell32 Control_RunDLL from a WebDAV UNC path), 'Network Configuration Manager' (uses net.exe to prepare WebClient/WebDAV access) and 'System Health Monitor' (control.exe loads a remote CPL from a hardcoded C2, 103.245.213.217). The CPL downloader fetches two ZIPs: one holding a Python 3.8 64-bit package plus a bootstrapper, the other an encrypted CosmicPulse payload. An AES key is stored under HKCU\Software\Classes\.mollis, and the bootstrapper decrypts the payload with that key plus an embedded AES-ECB key and runs the CosmicPulse (YESROBOT) backdoor. Microsoft states the backdoor's capabilities are unchanged from earlier versions.
Context from Google Threat Intelligence Group (October 2025): after the May 2025 LOSTKEYS exposure, COLDRIVER developed the COLDCOPY ClickFix lure, the NOROBOT DLL downloader (rundll32 export humanCheck/verifyme) and the YESROBOT Python 3.8 backdoor (HTTPS, AES-encrypted commands, host identity in the User-Agent header), later replaced by the PowerShell backdoor MAYBEROBOT (SIMPLEFIX). Zscaler ThreatLabz independently documented BAITSWITCH/SIMPLEFIX in September 2025. Microsoft also notes DarkSword iOS backdoor delivery observed in a March 2026 Atlantic Council-themed lure (Proofpoint report). Microsoft Defender detects the activity as Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse and Backdoor:Python/CosmicPulse, with behavioral alerts for suspicious LNK execution from a container, curl downloads, msiexec.exe behavior and Control Panel item use.
MITRE ATT&CK techniques used in TL-2026-2787
Defense Evasion
T1027 Obfuscated Files or Information; T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.002 Control Panel; T1218.007 Msiexec; T1553.005 Subvert Trust Controls
Persistence
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer
defense-impairment
Credential Access
T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
Affected products and versions in Star Blizzard (SEABORGIUM) RedFlick technique
- Microsoft — Windows
Vulnerable versions: Not version-specific; social-engineering delivery
Remediation for Star Blizzard (SEABORGIUM) RedFlick technique
Immediate actions
- Block the listed RedFlick MSI-host and CosmicPulse C2 domains and IPs at DNS, proxy and firewall
- Hunt for scheduled tasks named 'Internet Quality Test Connection', 'Network Configuration Manager' and 'System Health Monitor', and for the HKCU\Software\Classes\.mollis registry key
- Hunt for ssh.exe with PermitLocalCommand=yes and LocalCommand=cmd.exe, and conhost.exe launching curl
- Quarantine password-protected RAR/ZIP/VHDX attachments and review recipients who replied to conference or payment lures
Workarounds
- Enable ASR rules: block executable files unless they meet prevalence/trusted criteria, and block execution of potentially obfuscated scripts
- Enable network protection against malicious domains
- Restrict WebDAV/WebClient outbound access and outbound HTTP to newly observed hosts from control.exe and msiexec.exe
Longer-term hardening
- Deploy phishing-resistant authentication (FIDO2) and Conditional Access with identity-driven signals
- Enable Microsoft Defender for Office 365 Safe Links, Safe Attachments and zero-hour auto purge
- Run EDR in block mode with cloud-delivered protection and automatic sample submission
- Run Attack Simulator training on phishing lures and password-protected archives
Timeline of Star Blizzard (SEABORGIUM) RedFlick technique
- Star Blizzard (SEABORGIUM/COLDRIVER) targeting of academia, defense, government, NGOs and think tanks documented since at least 2019 (CISA AA23-341A, MITRE G1033)
- CISA, UK NCSC and partners publish AA23-341A assessing Star Blizzard as almost certainly subordinate to FSB Centre 18
- GTIG publicly exposes COLDRIVER's LOSTKEYS stealer; the group then rapidly retools with NOROBOT and YESROBOT (ClickFix/COLDCOPY chain)
- Zscaler ThreatLabz publishes BAITSWITCH and SIMPLEFIX analysis; GTIG follows in October 2025 with the COLDCOPY/NOROBOT/YESROBOT/MAYBEROBOT report
- January 2026: first observed RedFlick variant, using a password-protected ZIP containing a VHDX with an LNK disguised as a PDF and an ssh.exe PermitLocalCommand MSI download, against Ukrainian targets with a tax-audit lure
- March 2026: actor begins sending phishing from accounts on compromised cPanel/WordPress sites; conference lures (IISS, CES) target government, academia and tech, and an Atlantic Council-themed lure delivers the DarkSword iOS backdoor
- April 2026: persistence evolves from one to three coordinated scheduled tasks with WebDAV-based dynamic payload delivery; finance-themed roundtable lure targets financial organizations
- Digital Security Lab Ukraine documents a fake Ukraine Recovery Conference invitation campaign against Ukrainian CSOs: ZIP with VHDX and an LNK carrying PowerShell in its Description field, plus four scheduled tasks calling back to 103.160.59.97 and secure-dns-hub.com.
- June 2026: MAMA Summit and Chatham House London Conference lures target diplomatic staff, think tanks, NGOs and parliament
- July 2026: PDF-embedded PowerShell variant (magic header cAB, 208 bytes of Base64) delivered through USUBC-themed and Kyiv hotel water-outage lures
- Payment Advice Note campaign uses a unique password-protected ZIP per target.
- Mid-August 2026: image-based obfuscation added; a 'Payment Advice Note' lure targets an international financial organization
- NCSC updates its Star Blizzard advisory, documenting the actor's use of EvilGinx to bypass MFA, lookalike domains and mail-forwarding rules for persistence.
- Microsoft Threat Intelligence publishes the RedFlick analysis, reporting over 100 affected organizations, primarily in Ukraine then the US and UK
Update history for TL-2026-2787
- 2026-09-30 — Russia's Star Blizzard (FSB Center 18) Targets 100+ Organizations With Fake Event Invites to Deliver CosmicPulse Backdoor via RedFlick Technique: What changed No severity, exploitability or status change; existing fields already reflect ACTIVE / HIGH. New indicators (7) 1 new C2 IPv4 (89.125.66.183), 3 new SHA256 hashes from the fake-URC campaign, and the three RedFlick scheduled-tas
Sources cited for Star Blizzard (SEABORGIUM) RedFlick technique
- Star Blizzard refines phishing and malware delivery with the RedFlick technique
- Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spearphishing Campaigns (AA23-341A)
- GTIG: Russian COLDRIVER develops new malware families (NOROBOT, YESROBOT, MAYBEROBOT)
- Zscaler ThreatLabz: COLDRIVER updates arsenal with BAITSWITCH and SIMPLEFIX
- MITRE ATT&CK: Star Blizzard (G1033)
- UK NCSC: Russian FSB cyber actor Star Blizzard continues worldwide spear phishing campaigns
- Malpedia: NOROBOT (BAITSWITCH)
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data
Detection coverage for TL-2026-2787
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2787 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.