Phishing
Star Blizzard's RedFlick: fake invites, one-click backdoor
Russia's Star Blizzard sent 13 phishing waves this year to plant the CosmicPulse backdoor. How RedFlick works, what to block and how to hunt for it.
On September 29 Microsoft Threat Intelligence published a report on Star Blizzard, the Russian state group also tracked as Callisto and ColdRiver, which CISA ties to Centre 18 of Russia's Federal Security Service (FSB). Between January and August 2026 the group ran 13 large-scale phishing campaigns against more than 100 organizations, most of them in the United States and the United Kingdom. Every target works on Ukraine policy or support: think tanks, NGOs, government staff, academics, journalists and financial institutions.
The group also changed how it installs malware. Microsoft calls the new chain RedFlick. Earlier Star Blizzard attacks used ClickFix lures that needed the victim to take several manual steps; RedFlick needs one double-click on a file that looks like a PDF. No vulnerability is involved, so there is nothing to patch. What stops it is blocking the Windows features the chain depends on and hunting for the traces it leaves.
How it works
The first email is harmless: an invitation to a private roundtable or conference, or, in the early Ukrainian waves, a tax audit or fine notice. Because there is no link and no attachment, mail filters pass it. Only when the target replies does a second message arrive with a password-protected RAR or ZIP archive. The password is shown as an image in the email body, which keeps it away from scanners that read text, and the encryption stops the gateway from looking inside the archive.
Inside is an LNK file (a Windows shortcut) with a PDF icon and name. In the January wave it sat inside a VHDX file, a virtual hard disk that Windows mounts as a drive when it is opened. Double-clicking the shortcut opens a decoy PDF while a hidden conhost.exe window starts cmd.exe. From there the chain fetches a Windows Installer package and runs it silently with msiexec.exe /i <URL> /qn. The way it reaches that command changed over the year:
- In the VHDX wave, a hidden BAT script ran
ssh.exe, the OpenSSH client built into Windows, with-o PermitLocalCommand=yes -o LocalCommand="cmd.exe /c msiexec.exe ...". LocalCommand is meant to run a local command after an SSH connection; here it starts a process through a signed Microsoft binary. - From July, the shortcut downloads a PDF with
curl, and PowerShell finds Base64 text hidden inside the PDF, decodes it and runs the result.
The MSI then creates scheduled tasks with names chosen to look like housekeeping. Since April there have been three. "Internet Quality Test Connection" sends the computer or network name and the username to the attacker, encoded as UTF-16 Base64, and can run a remote DLL by calling Control_RunDLL in shell32.dll against a WebDAV path. "Network Configuration Manager" switches on the Windows WebDAV client, which lets Windows open files on a web server through \\server\path style addresses over HTTP instead of SMB. "System Health Monitor" uses control.exe, the Control Panel launcher, to run a remotely hosted Control Panel item.
That remote item is the downloader Microsoft tracks as NoroBot, also reported as BaitSwitch. Its only job is to download two ZIP files: one with a 64-bit Python 3.8 runtime and a bootstrapper script, the other with the encrypted CosmicPulse backdoor (also known as YESROBOT). An encrypted AES key is written to HKCU\Software\Classes\.mollis; the bootstrapper decrypts it with a key embedded in its code (AES in ECB mode) and uses it to unpack the backdoor. Every process along the way is a Windows binary or Python, so file reputation alone will not catch it.
What attackers are doing
The year started small. In January and February Star Blizzard posed as Ukrainian authorities and sent tax audit and fine notices to Ukr.net users, which looks like a test run of the new chain. In March it went international with invitations styled as coming from the IISS and the Atlantic Council, aimed at government officials, researchers, academics, media and NGOs.
June brought invitations to the "Chatham House London Conference 2026" and a MAMA Summit on Ukraine, sent to think tanks, NGOs, diplomatic staff and parliamentarians. In July the group used a USUBC roundtable lure and also went after Kyiv hotels. In August it sent "Payment Advice Note" archives to staff at international financial organizations. Microsoft also reports that the group sent some of this mail from accounts on compromised websites.
What to do
Block the steps you do not need
- Hold encrypted attachments from outside. In Exchange Online, a mail flow rule with the condition "Any attachment is password protected" can quarantine or flag these for review. Every RedFlick wave depended on a password-protected archive.
- Turn off the WebDAV client where nobody uses it.
Set-Service WebClient -StartupType DisabledandStop-Service WebClient, or the same through Group Policy. WebDAV runs over HTTP or HTTPS, so a port block at the firewall does not catch it; disabling the service does. - Stop workstations making outbound SSH connections. Block TCP 22 outbound at the perimeter for user subnets, and on Windows add a rule for the binary:
New-NetFirewallRule -DisplayName "Block ssh.exe out" -Direction Outbound -Program "%SystemRoot%\System32\OpenSSH\ssh.exe" -Action Block. Microsoft lists restricting outbound SSH among its mitigations. - Turn on the two attack surface reduction (ASR) rules Microsoft names: "Block executable files from running unless they meet a prevalence, age, or trusted list criterion" (
01443614-cd74-433a-b99e-2ecdc07bfc25) and "Block execution of potentially obfuscated scripts" (5beb7efe-fd9a-4556-801d-275e5ffc04cc). Try them in audit mode for a week first. Microsoft also recommends running Defender for Endpoint EDR in block mode.
Check whether you were already hit
On a single machine, look for the task names and the registry key:
Get-ScheduledTask | Where-Object { $_.TaskName -match 'Internet Quality Test Connection|Network Configuration Manager|System Health Monitor' }
Test-Path 'HKCU:\Software\Classes\.mollis'
Run the registry check as each user, or look under HKEY_USERS\<SID>\Software\Classes\.mollis. Across a fleet in Microsoft Defender XDR, Microsoft's published hunting query for the SSH launch is:
DeviceProcessEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has "ssh.exe"
| where ProcessCommandLine has "PermitLocalCommand=yes"
| where ProcessCommandLine has "LocalCommand=cmd.exe"
Extend the lookback to cover January onwards if your retention allows it. Microsoft's other queries look for conhost.exe with curl in its command line and for the three task names in process, registry and device events. Add two of your own: msiexec.exe with an http URL in its command line, and control.exe or rundll32.exe loading anything from a UNC path. Defender detects the family as Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse, so search alert history for those names too. Microsoft's report lists the domains and IP addresses used, including secure-dns-hub[.]com, which hosted the downloader from July and was still listed as active; load the full list into your proxy and DNS logs.
If you find it
Isolate the host and rebuild it rather than cleaning it: once CosmicPulse runs, the attacker has a backdoor working under the user's account. Reset that user's password, revoke their sessions in Entra ID, and check their mailbox for forwarding rules. Then look at who else received the same invitation: each campaign went to many recipients at once.
If your organization does policy, research, finance or diplomacy work connected to Ukraine, assume you are in scope. The person who replies to a plausible invitation is doing their job, so rely on the controls above, which hold whether or not someone replies.
We test exactly this kind of chain in safeguarding and hardening reviews, and write and tune detections like the queries above in security operations. If you want to know whether your estate would stop or spot RedFlick, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Microsoft Security Blog, SecurityWeek, BleepingComputer, The Hacker News, The Record, Field Effect.