Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine

Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver (TL-2026-2795), also tracked as RedFlick, is a high-severity advanced persistent threat campaign, first published 2026-09-29 and last reviewed 2026-09-30. It is attributed to Star Blizzard (Russia) with high confidence, affects Microsoft Windows endpoints (social-engineering delivery; no CVE), maps to 22 MITRE ATT&CK techniques (T1027, T1033, T1036.005), and is covered by 9 detection rules and 33 indicators of compromise.

Key facts for TL-2026-2795

Threat ID
TL-2026-2795
Also known as
RedFlick, CosmicPulse
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-09-29
Last reviewed
2026-09-30
Attribution
Star Blizzard
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, diplomacy, think tanks, ngo, finance, research, public-policy, news - media, academia
Target regions
united states of america, united kingdom, ukraine, Europe
Detection rules
9
Indicators of compromise
33
Updates
2026-09-30 · revalidated 1× · latest source

Malware and tooling in Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver

Malware and tooling: CosmicPulse, NOROBOT, RedFlick, YESROBOT

Microsoft reports that Russian FSB-affiliated Star Blizzard (SEABORGIUM, Callisto Group, TA446, COLDRIVER) shifted from targeted spear-phishing to mass-mailing, running at least 13 large campaigns since January 2026 against 100+ organizations, mainly in the US and UK plus Ukrainian entities. The RedFlick delivery technique uses LNK/VHDX/MSI chains and scheduled tasks to deploy the custom Python backdoor CosmicPulse after a single user interaction.

How Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver works

On 2026-09-29 Microsoft Threat Intelligence published analysis of Star Blizzard's new RedFlick malware delivery technique. Star Blizzard, attributed to the Russian FSB (Centre 18, per CISA advisory AA23-341A), historically ran low-volume, targeted credential-phishing spear-phishing. Since January 2026 Microsoft counted at least 13 larger campaigns, each with tens to hundreds of emails - a scale not previously seen from the actor - affecting more than 100 organizations, mostly in the United States and United Kingdom, in government, diplomacy, research/think tanks, NGOs, public policy, journalism and financial sectors tied to Ukraine. January-February 2026 campaigns focused on Ukrainian targets; from March 2026 targeting broadened globally.

Lures were varied: Ukrainian tax-audit result notifications and fine-payment debit notices, exclusive event invitations (IISS, CES, Atlantic Council, Chatham House, USUBC roundtable, Ukraine Recovery Conference), M&A and diplomatic-forum discussions, Kyiv hotel water-supply shutdown notices, and 'Payment Advice Note' messages to international financial organizations. Mail was sent from accounts the actor created on compromised cPanel/WordPress websites (reusing account names across compromised domains), a departure from earlier reliance on Proton Mail and Microsoft consumer accounts. Initial messages were often attachment-free; a follow-up delivered a password-protected RAR/ZIP (nested ZIP-in-RAR also seen), with the password supplied as an image in the email.

January 2026 chain: password-protected ZIP containing a VHDX holding a malicious LNK disguised as a PDF, a hidden BAT script and a decoy PDF. Opening the LNK launches conhost.exe hidden, cmd.exe runs the BAT, the decoy PDF opens, and ssh.exe is abused with PermitLocalCommand/LocalCommand to download an MSI from actor infrastructure. The MSI uses control.exe to create a scheduled task that pulls a CosmicPulse CPL downloader (Control Panel applet DLL; tracked as NOROBOT/BAITSWITCH/YESROBOT lineage in reporting). By April 2026 the MSI created three scheduled tasks: 'Internet Quality Test Connection' (sends Base64/UTF-16-encoded computer name, network name and username to C2 and runs remote DLLs via Shell32 Control_RunDLL over WebDAV UNC paths), 'Network Configuration Manager' (invokes net.exe to start WebClient/WebDAV) and 'System Health Monitor' (control.exe to run CosmicPulse downloader stages from C2). In July 2026 a variant used an LNK that ran conhost.exe with curl to fetch a PDF from the actor's server; PowerShell located the magic header 'cAB' in the PDF, extracted 208 bytes of Base64, decoded and executed it to download and install the MSI.

CosmicPulse is a Python-based backdoor: the CPL downloader retrieves two ZIPs from C2 - the first with a Python 3.8 64-bit package and bootstrapper, the second with an encrypted CosmicPulse payload. The bootstrapper reads an encrypted AES key from HKCU\Software\Classes\.mollis, decrypts it with AES-ECB using an embedded key, decodes the payload and runs it, giving the operator remote command execution and persistent access. Microsoft detections: Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse, Backdoor:Python/CosmicPulse, plus behavioral alerts for suspicious LNK execution from a container, curl download, msiexec and Control Panel item use. C2 infrastructure rotated roughly monthly; secure-dns-hub.com remained active as of 2026-09-29.

MITRE ATT&CK techniques used in TL-2026-2795

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type; T1112 Modify Registry; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1218.002 Control Panel; T1218.007 Msiexec; T1564.003 Hidden Window

Discovery

T1033 System Owner/User Discovery; T1082 System Information Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer

Initial Access

T1566.001 Spearphishing Attachment

Resource Development

T1583.001 Domains; T1584 Compromise Infrastructure

Affected products and versions in Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver

  • Microsoft — Windows endpoints (social-engineering delivery; no CVE)
    Vulnerable versions: Not version-specific

Remediation for Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver

Immediate actions

  • Hunt for scheduled tasks named 'Internet Quality Test Connection', 'Network Configuration Manager' and 'System Health Monitor'
  • Block the listed domains and IPs at proxy/DNS/firewall and search historic logs for them
  • Quarantine password-protected RAR/ZIP, VHDX and LNK attachments; isolate affected hosts and preserve email threads and archives
  • Search for the registry key HKCU\Software\Classes\.mollis and Python 3.8 packages in user-writable paths

Workarounds

  • Alert on ssh.exe with PermitLocalCommand=yes and LocalCommand, and on conhost.exe launching curl
  • Block or alert on VHDX mounting and LNK execution originating from containers

Longer-term hardening

  • Deploy phishing-resistant authentication and Conditional Access with continuous access evaluation
  • Enable Defender for Office 365 Safe Links (recheck on click), Safe Attachments and zero-hour auto-purge
  • Enable EDR in block mode, cloud-delivered protection, attack surface reduction rules and network protection
  • Restrict outbound SSH via Windows Firewall; train users on password-protected archive lures

Timeline of Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver

  • CISA/Microsoft advisory AA23-341A attributes Star Blizzard (SEABORGIUM/COLDRIVER) to FSB Centre 18 and documents its worldwide spear-phishing (month-level context for later escalation)
  • Late May 2025: Google Threat Intelligence observes COLDRIVER deploying the NOROBOT loader and the Python YESROBOT backdoor, ancestors of CosmicPulse, followed in June by MAYBEROBOT.
  • January 2026: first RedFlick-era mass campaign against Ukrainian targets using tax-audit lures; ZIP > VHDX > LNK > ssh.exe MSI download chain (infra etia.ca, 103.245.231.248); date is month-level
  • February 2026: continued Ukraine-focused campaigns with new infrastructure (groy.cc, muvb.net, 2.57.241.246, 89.125.209.168); date is month-level
  • March 2026: DarkSword iOS exploit-kit links seen in an Atlantic Council-themed Star Blizzard mailing; month-level date.
  • March 2026: targeting expands beyond Ukraine to global think tanks and policy organizations (Atlantic Council-themed lures; matjk.click, bpdaersa.click, 103.245.231.79); date is month-level
  • April 2026: MSI installers create the three RedFlick scheduled tasks (Internet Quality Test Connection, Network Configuration Manager, System Health Monitor); infra itechx.tel, 45.84.59.66; date is month-level
  • June 2026: Chatham House / Ukraine Recovery Conference-themed lures with password-protected RAR (guach.net, ruten.observer); date is month-level
  • July 2026: new variant hides a Base64 PowerShell payload (208 bytes after magic header 'cAB') inside a PDF fetched via curl; USUBC roundtable lure; infra byveo.org, qumel.link, secure-dns-hub.com, 103.160.59.97; date is month-level
  • August 2026: 'Payment Advice Note' campaign against financial organizations (cyrna.top, drasw.club); date is month-level
  • Microsoft publishes RedFlick/CosmicPulse analysis (13+ campaigns, 100+ organizations); secure-dns-hub.com still active

Update history for TL-2026-2795

Sources cited for Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver

More in apt

Detection coverage for TL-2026-2795

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2795 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats