RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
Star Blizzard ran 13 RedFlick phishing campaigns in 2026, deploying CosmicPulse against more than 100 organizations.
Microsoft says Star Blizzard, which CISA attributes to Russia's FSB Center 18, ran at least 13 RedFlick phishing campaigns from January to August 2026 against more than 100 organizations, mainly in the United States and United Kingdom, plus Ukrainian and Ukraine-related targets. After an attachment-free lure, the group sends a password-protected ZIP or RAR with the password in an image, then uses disguised LNK files, scheduled tasks, WebDAV, and a CPL downloader to install the CosmicPulse backdoor, also known as YESROBOT. A July variant nests a RAR inside a ZIP and hides Base64 in a PDF that PowerShell decodes to fetch another MSI. Microsoft urges hunting for the three named scheduled tasks and related Windows binary abuse.