← Back to news
BleepingComputer30 Sept 2026 · 2 min read

Microsoft details RedFlick malware delivery method linked to Star Blizzard

Microsoft says the Russia-linked threat actor known as Star Blizzard has adopted a malware delivery method it calls RedFlick, which is designed to reduce the amount of interaction required from phishi...

Microsoft says the Russia-linked threat actor known as Star Blizzard has adopted a malware delivery method it calls RedFlick, which is designed to reduce the amount of interaction required from phishing targets before an infection begins.

According to Microsoft’s analysis, the campaigns start with phishing emails that may pose as invitations or messages from trusted contacts. A follow-up email carries a password-protected ZIP or RAR archive. Inside is a VHDX virtual disk image containing a Windows shortcut file disguised as a PDF document.

When a recipient opens the shortcut, a decoy PDF is displayed while commands execute in the background. Those commands download an MSI installer that creates several scheduled tasks with names intended to resemble routine Windows or network-maintenance functions.

Multi-stage deployment chain

Microsoft said the scheduled tasks divide responsibilities across the infection process. One task gathers basic device and user information and can run a remotely supplied DLL. Another configures WebDAV-related functionality, while a third uses the Windows Control Panel executable to launch a remotely hosted payload.

The next stage involves downloader components identified as NOROBOT and BAITSWITCH, delivered as Control Panel applet files. These components retrieve archives containing a Python runtime and a bootstrapper that decrypts and launches the CosmicPulse backdoor.

CosmicPulse can run Python code provided by operators, download and execute files, and collect documents from compromised devices, Microsoft said. The company noted that these capabilities are consistent with earlier public reporting on the malware.

Targets and defensive measures

Star Blizzard, which has been active since at least 2017, has previously used different social-engineering and payload-delivery approaches. Microsoft said RedFlick is significant because a victim generally needs only to open the malicious shortcut, unlike methods that require users to copy commands or complete several manual steps.

The observed campaigns reportedly targeted Ukrainian individuals and organizations, as well as NGOs, think tanks, government entities, and financial institutions connected to support for Ukraine. Microsoft said it had identified at least 13 large-scale phishing operations affecting more than 100 organizations, primarily in the United States and United Kingdom, during 2026.

  • Verify unexpected messages through known contact channels.
  • Use phishing-resistant authentication and Conditional Access controls.
  • Deploy email filtering and endpoint detection and response tools, including block-mode protections where available.
  • Train users to treat password-protected archives, disk images, and shortcut files as potentially suspicious.
Share this article:TwitterLinkedIn