RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
Star Blizzard ran 13 RedFlick phishing campaigns in 2026, deploying CosmicPulse against more than 100 organizations.
Microsoft says Star Blizzard, which CISA attributes to Russia's FSB Center 18, ran at least 13 RedFlick phishing campaigns from January to August 2026 against more than 100 organizations, mainly in the United States and United Kingdom, plus Ukrainian and Ukraine-related targets. After an attachment-free lure, the group sends a password-protected ZIP or RAR with the password in an image, then uses disguised LNK files, scheduled tasks, WebDAV, and a CPL downloader to install the CosmicPulse backdoor, also known as YESROBOT. A July variant nests a RAR inside a ZIP and hides Base64 in a PDF that PowerShell decodes to fetch another MSI. Microsoft urges hunting for the three named scheduled tasks and related Windows binary abuse.
- At least 13 campaigns hit more than 100 organizations in 2026.
- Follow-up emails carry password-protected ZIP or RAR archives.
- Three scheduled tasks deploy a CPL CosmicPulse downloader.
- A July variant hid Base64 in a PDF decoded by PowerShell.
- CosmicPulse is also known as YESROBOT; the downloader as NOROBOT.
Full article794 words · extracted from gbhackers.com · click to collapse
Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked by Microsoft as RedFlick.
Microsoft Threat Intelligence reported that the group, which CISA attributes to Russia’s Federal Security Service (FSB) Center 18, conducted at least 13 phishing campaigns between January and August 2026.
The activity affected more than 100 organizations, primarily in the United States and United Kingdom, with targets including Ukrainian institutions, governments, NGOs, think tanks, research organizations, diplomatic staff, media entities, and financial institutions connected to support for Ukraine.
Star Blizzard historically relied on tightly targeted spear-phishing campaigns, often impersonating political figures, academics, or diplomatic contacts.
In 2026, however, the actor broadened its initial outreach, sending tens to hundreds of emails per campaign to identify recipients willing to engage before delivering malware.
The lures commonly impersonated invitations to closed-door policy discussions, international conferences, financial events, and Ukraine-related forums.
In some cases, phishing emails appeared to originate from internal contacts or reputable organizations known to the intended target.
A key operational change involved the use of email accounts created on compromised websites, including sites hosted on cPanel and WordPress infrastructure.
Microsoft assessed with high confidence that Star Blizzard compromised those websites to create and operate sender accounts, helping the actor avoid depending exclusively on free email providers and increasing the credibility of phishing messages.
The RedFlick chain begins only after a recipient responds to an attachment-free phishing email.
Star Blizzard then sends a follow-up message containing a password-protected ZIP or RAR archive, while providing the password as an image embedded in the email.
This delivery method complicates automated email inspection because security products may be unable to scan encrypted archive contents before they reach the endpoint.
RedFlick Backdoor
The follow-up also arrives within an apparently legitimate email conversation, increasing the likelihood that a recipient will regard the attachment as an expected document.
Fieldeffect Researchers observed that, RedFlick uses password-protected archives, scheduled tasks, WebDAV, and disguised Windows components to install the CosmicPulse backdoor on targeted systems.
Earlier 2026 campaigns used ZIP archives containing VHDX virtual disk images. The VHDX file included a malicious Windows shortcut, or LNK, disguised as a PDF document, a hidden BAT script, and a decoy PDF.
When a victim launched the shortcut, the script opened the decoy while using legitimate Windows binaries and SSH functionality to download and execute a remote MSI installer.
Beginning in April, RedFlick installers moved beyond creating a single scheduled task.
Microsoft observed MSI installers creating three scheduled tasks masquerading as benign Windows or network-management components: Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.
The first task sends basic host data, including the computer or network name and username, to command-and-control infrastructure. It can also invoke attacker-controlled DLLs remotely through Control_RunDLL and Shell32.dll.
A second task enables the WebClient functionality required to access WebDAV paths, allowing Windows to retrieve remote resources over HTTP or HTTPS while treating them like network shares.
The third task uses control.exe to retrieve and execute a remote Control Panel applet, or CPL file. That component functions as a CosmicPulse downloader, installing a Python environment, decrypting the final payload, and launching the CosmicPulse backdoor.
The malware is also publicly known as YESROBOT, while its downloader has been referred to as NOROBOT or BAITSWITCH.
In July, Star Blizzard introduced another RedFlick variation that nested a password-protected RAR archive inside a ZIP file.
The archive exposed an LNK file which used conhost.exe and curl to download a PDF from actor-controlled infrastructure.
Rather than serving only as a decoy, the PDF concealed Base64-encoded data. A PowerShell command searched the downloaded file for a cAB marker, extracted 208 bytes of encoded content, decoded it, and executed the result to download another MSI installer.
The installer then attempted to create additional scheduled tasks and deploy the CPL-based CosmicPulse downloader.
Defenders should investigate password-protected archives delivered after attachment-free email exchanges, especially where passwords are embedded in images or senders claim an attachment was previously omitted.
Endpoint telemetry is critical because mail-layer controls may have limited visibility into encrypted archives.
High-value hunting signals include VHDX mounting, LNK files masquerading as PDFs, conhost.exe launching curl, suspicious msiexec.exe behavior, PowerShell extracting content from PDFs, ssh.exe executed with PermitLocalCommand, WebDAV activity, and creation of the three scheduled-task names associated with RedFlick.
Microsoft also recommends phishing-resistant authentication, Conditional Access, Safe Links, Safe Attachments, endpoint detection and response in block mode, and controls that prevent execution of obfuscated scripts.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.