Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)

Star Blizzard (SEABORGIUM) RedFlick technique (TL-2026-2787), also tracked as RedFlick, is a high-severity advanced persistent threat campaign, first published 2026-09-29 and last reviewed 2026-09-30. It is attributed to Star Blizzard (Russia) with high confidence, affects Microsoft Windows, maps to 20 MITRE ATT&CK techniques (T1027, T1027.003, T1036.005), and is covered by 9 detection rules and 36 indicators of compromise.

Key facts for TL-2026-2787

Threat ID
TL-2026-2787
Also known as
RedFlick, CosmicPulse, YESROBOT, NOROBOT, BAITSWITCH
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-09-29
Last reviewed
2026-09-30
Attribution
Star Blizzard
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, ngo, think-tank, finance, academia, diplomatic, hospitality, technology
Target regions
ukraine, united states of america, united kingdom, Europe
Detection rules
9
Indicators of compromise
36
Updates
2026-09-30 · revalidated 1× · latest source

Malware and tooling in Star Blizzard (SEABORGIUM) RedFlick technique

Malware and tooling: MAYBEROBOT, NOROBOT, YESROBOT

Microsoft Threat Intelligence reports that Russian FSB Centre 18 actor Star Blizzard (SEABORGIUM/COLDRIVER) has shifted from targeted spear-phishing to large-scale phishing and uses the RedFlick technique, in which scheduled tasks deploy backdoors with fewer user interactions than earlier ClickFix chains. Payloads include the Python backdoor CosmicPulse (YESROBOT) and a Control Panel applet (CPL) downloader (NOROBOT/BAITSWITCH); more than 100 organizations were affected, primarily in Ukraine and then the US and UK.

How Star Blizzard (SEABORGIUM) RedFlick technique works

Microsoft Threat Intelligence (2026-09-29) describes how Star Blizzard, a Russian state actor assessed by CISA and partner agencies (AA23-341A) as almost certainly subordinate to FSB Centre 18, evolved during 2026 from manual, targeted spear-phishing to mass-mailing campaigns of tens to hundreds of emails per wave. Lures impersonate legitimate organizations: conference and roundtable invitations (IISS, Chatham House, Atlantic Council-themed, USUBC, MAMA Summit, Future of Liberty/Peace Operations forums), Ukrainian-language tax and fine-payment notices, a Kyiv water-supply outage notice aimed at hotels, and a payment advice note aimed at an international financial organization. From March 2026 onward the actor also created accounts on compromised cPanel/WordPress-hosted sites to send phishing. Targets include Ukrainian individuals, NGOs, think tanks, governments and financial institutions supporting Ukraine; over 100 organizations were affected, primarily in Ukraine and then the US and UK.

After a recipient replies, a follow-up email delivers a password-protected RAR/ZIP archive, with the password shown as an image to evade email filtering. The archive starts the RedFlick chain, which needs a single user interaction. In the January 2026 variant a ZIP holds a VHDX containing an LNK disguised as a PDF and a hidden BAT directory. The LNK launches a hidden conhost.exe and cmd.exe, and the BAT opens a decoy PDF and runs ssh.exe with PermitLocalCommand enabled to download an MSI from attacker infrastructure. The MSI creates a scheduled task that uses control.exe to fetch a CPL downloader (CosmicPulse downloader, aka NOROBOT/BAITSWITCH). In the July 2026 variant a RAR nested in a ZIP holds an LNK that uses conhost.exe and curl to download a PDF. PowerShell locates the magic header 'cAB' in the PDF, extracts 208 bytes of Base64 data, and decodes a command that downloads the MSI, which creates two scheduled tasks. In mid-August 2026 the actor added image-based/steganographic obfuscation.

From April 2026 persistence moved to three coordinated scheduled tasks masquerading as Windows components: 'Internet Quality Test Connection' (beacons a UTF-16 Base64 string containing network/computer name and username to the C2 and runs an attacker DLL via Shell32 Control_RunDLL from a WebDAV UNC path), 'Network Configuration Manager' (uses net.exe to prepare WebClient/WebDAV access) and 'System Health Monitor' (control.exe loads a remote CPL from a hardcoded C2, 103.245.213.217). The CPL downloader fetches two ZIPs: one holding a Python 3.8 64-bit package plus a bootstrapper, the other an encrypted CosmicPulse payload. An AES key is stored under HKCU\Software\Classes\.mollis, and the bootstrapper decrypts the payload with that key plus an embedded AES-ECB key and runs the CosmicPulse (YESROBOT) backdoor. Microsoft states the backdoor's capabilities are unchanged from earlier versions.

Context from Google Threat Intelligence Group (October 2025): after the May 2025 LOSTKEYS exposure, COLDRIVER developed the COLDCOPY ClickFix lure, the NOROBOT DLL downloader (rundll32 export humanCheck/verifyme) and the YESROBOT Python 3.8 backdoor (HTTPS, AES-encrypted commands, host identity in the User-Agent header), later replaced by the PowerShell backdoor MAYBEROBOT (SIMPLEFIX). Zscaler ThreatLabz independently documented BAITSWITCH/SIMPLEFIX in September 2025. Microsoft also notes DarkSword iOS backdoor delivery observed in a March 2026 Atlantic Council-themed lure (Proofpoint report). Microsoft Defender detects the activity as Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse and Backdoor:Python/CosmicPulse, with behavioral alerts for suspicious LNK execution from a container, curl downloads, msiexec.exe behavior and Control Panel item use.

MITRE ATT&CK techniques used in TL-2026-2787

Defense Evasion

T1027 Obfuscated Files or Information; T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.002 Control Panel; T1218.007 Msiexec; T1553.005 Subvert Trust Controls

Persistence

T1053.005 Scheduled Task

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer

defense-impairment

T1112 Modify Registry

Credential Access

T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1586.002 Compromise Accounts

Affected products and versions in Star Blizzard (SEABORGIUM) RedFlick technique

  • Microsoft — Windows
    Vulnerable versions: Not version-specific; social-engineering delivery

Remediation for Star Blizzard (SEABORGIUM) RedFlick technique

Immediate actions

  • Block the listed RedFlick MSI-host and CosmicPulse C2 domains and IPs at DNS, proxy and firewall
  • Hunt for scheduled tasks named 'Internet Quality Test Connection', 'Network Configuration Manager' and 'System Health Monitor', and for the HKCU\Software\Classes\.mollis registry key
  • Hunt for ssh.exe with PermitLocalCommand=yes and LocalCommand=cmd.exe, and conhost.exe launching curl
  • Quarantine password-protected RAR/ZIP/VHDX attachments and review recipients who replied to conference or payment lures

Workarounds

  • Enable ASR rules: block executable files unless they meet prevalence/trusted criteria, and block execution of potentially obfuscated scripts
  • Enable network protection against malicious domains
  • Restrict WebDAV/WebClient outbound access and outbound HTTP to newly observed hosts from control.exe and msiexec.exe

Longer-term hardening

  • Deploy phishing-resistant authentication (FIDO2) and Conditional Access with identity-driven signals
  • Enable Microsoft Defender for Office 365 Safe Links, Safe Attachments and zero-hour auto purge
  • Run EDR in block mode with cloud-delivered protection and automatic sample submission
  • Run Attack Simulator training on phishing lures and password-protected archives

Timeline of Star Blizzard (SEABORGIUM) RedFlick technique

  • Star Blizzard (SEABORGIUM/COLDRIVER) targeting of academia, defense, government, NGOs and think tanks documented since at least 2019 (CISA AA23-341A, MITRE G1033)
  • CISA, UK NCSC and partners publish AA23-341A assessing Star Blizzard as almost certainly subordinate to FSB Centre 18
  • GTIG publicly exposes COLDRIVER's LOSTKEYS stealer; the group then rapidly retools with NOROBOT and YESROBOT (ClickFix/COLDCOPY chain)
  • Zscaler ThreatLabz publishes BAITSWITCH and SIMPLEFIX analysis; GTIG follows in October 2025 with the COLDCOPY/NOROBOT/YESROBOT/MAYBEROBOT report
  • January 2026: first observed RedFlick variant, using a password-protected ZIP containing a VHDX with an LNK disguised as a PDF and an ssh.exe PermitLocalCommand MSI download, against Ukrainian targets with a tax-audit lure
  • March 2026: actor begins sending phishing from accounts on compromised cPanel/WordPress sites; conference lures (IISS, CES) target government, academia and tech, and an Atlantic Council-themed lure delivers the DarkSword iOS backdoor
  • April 2026: persistence evolves from one to three coordinated scheduled tasks with WebDAV-based dynamic payload delivery; finance-themed roundtable lure targets financial organizations
  • Digital Security Lab Ukraine documents a fake Ukraine Recovery Conference invitation campaign against Ukrainian CSOs: ZIP with VHDX and an LNK carrying PowerShell in its Description field, plus four scheduled tasks calling back to 103.160.59.97 and secure-dns-hub.com.
  • June 2026: MAMA Summit and Chatham House London Conference lures target diplomatic staff, think tanks, NGOs and parliament
  • July 2026: PDF-embedded PowerShell variant (magic header cAB, 208 bytes of Base64) delivered through USUBC-themed and Kyiv hotel water-outage lures
  • Payment Advice Note campaign uses a unique password-protected ZIP per target.
  • Mid-August 2026: image-based obfuscation added; a 'Payment Advice Note' lure targets an international financial organization
  • NCSC updates its Star Blizzard advisory, documenting the actor's use of EvilGinx to bypass MFA, lookalike domains and mail-forwarding rules for persistence.
  • Microsoft Threat Intelligence publishes the RedFlick analysis, reporting over 100 affected organizations, primarily in Ukraine then the US and UK

Update history for TL-2026-2787

Sources cited for Star Blizzard (SEABORGIUM) RedFlick technique

More in apt

Detection coverage for TL-2026-2787

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2787 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats