Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver (TL-2026-2795), also tracked as RedFlick, is a high-severity advanced persistent threat campaign, first published 2026-09-29 and last reviewed 2026-09-30. It is attributed to Star Blizzard (Russia) with high confidence, affects Microsoft Windows endpoints (social-engineering delivery; no CVE), maps to 22 MITRE ATT&CK techniques (T1027, T1033, T1036.005), and is covered by 9 detection rules and 33 indicators of compromise.
Key facts for TL-2026-2795
- Threat ID
- TL-2026-2795
- Also known as
- RedFlick, CosmicPulse
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-09-29
- Last reviewed
- 2026-09-30
- Attribution
- Star Blizzard
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomacy, think tanks, ngo, finance, research, public-policy, news - media, academia
- Target regions
- united states of america, united kingdom, ukraine, Europe
- Detection rules
- 9
- Indicators of compromise
- 33
- Updates
- 2026-09-30 · revalidated 1× · latest source
Malware and tooling in Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver
Malware and tooling: CosmicPulse, NOROBOT, RedFlick, YESROBOT
Microsoft reports that Russian FSB-affiliated Star Blizzard (SEABORGIUM, Callisto Group, TA446, COLDRIVER) shifted from targeted spear-phishing to mass-mailing, running at least 13 large campaigns since January 2026 against 100+ organizations, mainly in the US and UK plus Ukrainian entities. The RedFlick delivery technique uses LNK/VHDX/MSI chains and scheduled tasks to deploy the custom Python backdoor CosmicPulse after a single user interaction.
How Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver works
On 2026-09-29 Microsoft Threat Intelligence published analysis of Star Blizzard's new RedFlick malware delivery technique. Star Blizzard, attributed to the Russian FSB (Centre 18, per CISA advisory AA23-341A), historically ran low-volume, targeted credential-phishing spear-phishing. Since January 2026 Microsoft counted at least 13 larger campaigns, each with tens to hundreds of emails - a scale not previously seen from the actor - affecting more than 100 organizations, mostly in the United States and United Kingdom, in government, diplomacy, research/think tanks, NGOs, public policy, journalism and financial sectors tied to Ukraine. January-February 2026 campaigns focused on Ukrainian targets; from March 2026 targeting broadened globally.
Lures were varied: Ukrainian tax-audit result notifications and fine-payment debit notices, exclusive event invitations (IISS, CES, Atlantic Council, Chatham House, USUBC roundtable, Ukraine Recovery Conference), M&A and diplomatic-forum discussions, Kyiv hotel water-supply shutdown notices, and 'Payment Advice Note' messages to international financial organizations. Mail was sent from accounts the actor created on compromised cPanel/WordPress websites (reusing account names across compromised domains), a departure from earlier reliance on Proton Mail and Microsoft consumer accounts. Initial messages were often attachment-free; a follow-up delivered a password-protected RAR/ZIP (nested ZIP-in-RAR also seen), with the password supplied as an image in the email.
January 2026 chain: password-protected ZIP containing a VHDX holding a malicious LNK disguised as a PDF, a hidden BAT script and a decoy PDF. Opening the LNK launches conhost.exe hidden, cmd.exe runs the BAT, the decoy PDF opens, and ssh.exe is abused with PermitLocalCommand/LocalCommand to download an MSI from actor infrastructure. The MSI uses control.exe to create a scheduled task that pulls a CosmicPulse CPL downloader (Control Panel applet DLL; tracked as NOROBOT/BAITSWITCH/YESROBOT lineage in reporting). By April 2026 the MSI created three scheduled tasks: 'Internet Quality Test Connection' (sends Base64/UTF-16-encoded computer name, network name and username to C2 and runs remote DLLs via Shell32 Control_RunDLL over WebDAV UNC paths), 'Network Configuration Manager' (invokes net.exe to start WebClient/WebDAV) and 'System Health Monitor' (control.exe to run CosmicPulse downloader stages from C2). In July 2026 a variant used an LNK that ran conhost.exe with curl to fetch a PDF from the actor's server; PowerShell located the magic header 'cAB' in the PDF, extracted 208 bytes of Base64, decoded and executed it to download and install the MSI.
CosmicPulse is a Python-based backdoor: the CPL downloader retrieves two ZIPs from C2 - the first with a Python 3.8 64-bit package and bootstrapper, the second with an encrypted CosmicPulse payload. The bootstrapper reads an encrypted AES key from HKCU\Software\Classes\.mollis, decrypts it with AES-ECB using an embedded key, decodes the payload and runs it, giving the operator remote command execution and persistent access. Microsoft detections: Trojan:Script/RedFlick, Backdoor:Script/CosmicPulse, Backdoor:Python/CosmicPulse, plus behavioral alerts for suspicious LNK execution from a container, curl download, msiexec and Control Panel item use. C2 infrastructure rotated roughly monthly; secure-dns-hub.com remained active as of 2026-09-29.
MITRE ATT&CK techniques used in TL-2026-2795
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type; T1112 Modify Registry; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1218.002 Control Panel; T1218.007 Msiexec; T1564.003 Hidden Window
Discovery
T1033 System Owner/User Discovery; T1082 System Information Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1566.001 Spearphishing Attachment
Resource Development
Affected products and versions in Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver
- Microsoft — Windows endpoints (social-engineering delivery; no CVE)
Vulnerable versions: Not version-specific
Remediation for Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver
Immediate actions
- Hunt for scheduled tasks named 'Internet Quality Test Connection', 'Network Configuration Manager' and 'System Health Monitor'
- Block the listed domains and IPs at proxy/DNS/firewall and search historic logs for them
- Quarantine password-protected RAR/ZIP, VHDX and LNK attachments; isolate affected hosts and preserve email threads and archives
- Search for the registry key HKCU\Software\Classes\.mollis and Python 3.8 packages in user-writable paths
Workarounds
- Alert on ssh.exe with PermitLocalCommand=yes and LocalCommand, and on conhost.exe launching curl
- Block or alert on VHDX mounting and LNK execution originating from containers
Longer-term hardening
- Deploy phishing-resistant authentication and Conditional Access with continuous access evaluation
- Enable Defender for Office 365 Safe Links (recheck on click), Safe Attachments and zero-hour auto-purge
- Enable EDR in block mode, cloud-delivered protection, attack surface reduction rules and network protection
- Restrict outbound SSH via Windows Firewall; train users on password-protected archive lures
Timeline of Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver
- CISA/Microsoft advisory AA23-341A attributes Star Blizzard (SEABORGIUM/COLDRIVER) to FSB Centre 18 and documents its worldwide spear-phishing (month-level context for later escalation)
- Late May 2025: Google Threat Intelligence observes COLDRIVER deploying the NOROBOT loader and the Python YESROBOT backdoor, ancestors of CosmicPulse, followed in June by MAYBEROBOT.
- January 2026: first RedFlick-era mass campaign against Ukrainian targets using tax-audit lures; ZIP > VHDX > LNK > ssh.exe MSI download chain (infra etia.ca, 103.245.231.248); date is month-level
- February 2026: continued Ukraine-focused campaigns with new infrastructure (groy.cc, muvb.net, 2.57.241.246, 89.125.209.168); date is month-level
- March 2026: DarkSword iOS exploit-kit links seen in an Atlantic Council-themed Star Blizzard mailing; month-level date.
- March 2026: targeting expands beyond Ukraine to global think tanks and policy organizations (Atlantic Council-themed lures; matjk.click, bpdaersa.click, 103.245.231.79); date is month-level
- April 2026: MSI installers create the three RedFlick scheduled tasks (Internet Quality Test Connection, Network Configuration Manager, System Health Monitor); infra itechx.tel, 45.84.59.66; date is month-level
- June 2026: Chatham House / Ukraine Recovery Conference-themed lures with password-protected RAR (guach.net, ruten.observer); date is month-level
- July 2026: new variant hides a Base64 PowerShell payload (208 bytes after magic header 'cAB') inside a PDF fetched via curl; USUBC roundtable lure; infra byveo.org, qumel.link, secure-dns-hub.com, 103.160.59.97; date is month-level
- August 2026: 'Payment Advice Note' campaign against financial organizations (cyrna.top, drasw.club); date is month-level
- Microsoft publishes RedFlick/CosmicPulse analysis (13+ campaigns, 100+ organizations); secure-dns-hub.com still active
Update history for TL-2026-2795
- 2026-09-30 — Star Blizzard RedFlick Campaign Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse (YESROBOT) Backdoor: What changed No field escalation; severity HIGH and exploitability ACTIVE unchanged. New indicators (6) 3 CosmicPulse payload-hosting domains (gliderrompercycl.com, divekickspolic.org, stuseamandesilt.org) and the 3 masquerading scheduled-t
Sources cited for Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver
- Star Blizzard refines phishing and malware delivery with the RedFlick technique (Microsoft Security Blog)
- Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond (CyberScoop)
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor (The Hacker News)
- Star Blizzard scales phishing operations with RedFlick malware delivery (Field Effect)
- Star Blizzard RedFlick Phishing Uses Windows Tools to Deploy CosmicPulse Backdoor (WindowsForum)
- Star Blizzard Expands Phishing With RedFlick and New Backdoor Delivery Chains (Mallory)
- Star Blizzard refines phishing and malware delivery with the RedFlick technique (TheWindowsUpdate mirror)
- Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spearphishing Campaigns (CISA AA23-341A)
- Star Blizzard increases sophistication and evasion in ongoing attacks (Microsoft Security Blog)
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data
Detection coverage for TL-2026-2795
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2795 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.