The Russian state-sponsored threat actor known as Star Blizzard has significantly automated its phishing operations, transitioning from high-touch social engineering to a streamlined malware delivery system dubbed RedFlick. According to a report published by Microsoft Threat Intelligence on September 29, 2026, the group has utilized this technique in at least 13 distinct campaigns between January and August 2026, affecting more than 100 organizations.
Star Blizzard, also tracked as SEABORGIUM or ColdRiver, is attributed to Centre 18 of the Russian Federal Security Service (FSB). Historically known for labor-intensive spear-phishing that required building rapport with targets over weeks, the group is now utilizing compromised WordPress and cPanel infrastructure to distribute malicious payloads at an industrial scale. This shift targets government agencies, NGOs, and think tanks, particularly those involved in supporting Ukraine.

The Mechanics of RedFlick
The RedFlick technique marks a departure from the group’s 2025 “ClickFix” method, which involved several manual steps for the victim. The new workflow reduces victim interaction to a single action, typically opening a file within a password-protected archive. By using password-protected ZIP or RAR files, the attackers effectively bypass many standard email security filters that cannot inspect the encrypted contents.
Inside these archives, victims find a Virtual Hard Disk (VHDX) file. When mounted, the VHDX provides an environment for the execution of the “BAITSWITCH” (also known as NOROBOT) downloader. This intermediate stage is responsible for the final delivery of CosmicPulse, a custom Python-based backdoor designed for persistent access and data exfiltration. Reporting from SecurityWeek confirms that this backdoor is the primary tool used by the FSB-linked group in its recent wave of attacks targeting organizations involved in supporting Ukraine.
Persistence and Stealth Tactics
Once the RedFlick infection chain is triggered, the malware establishes persistence by creating three specific scheduled tasks on the infected Windows system. These tasks are named to mimic legitimate administrative or diagnostic tools, making them less likely to be flagged by casual inspection or basic security monitoring:
- Internet Quality Test Connection: Used to maintain communication with the command-and-control (C2) server.
- Network Configuration Manager: Manages the backdoor’s networking requirements and potential lateral movement.
- System Health Monitor: Acts as a watchdog for the malware process, ensuring it restarts if terminated.
The industrialization of these attacks is further evidenced by the group’s move away from consumer email services like Proton or Microsoft personal accounts. By leveraging hijacked legitimate websites and hosting control panels, the actors gain higher domain reputation for their phishing emails, increasing the likelihood that their messages reach the target’s primary inbox.
Security researchers suggest that organizations can mitigate the risk of RedFlick by restricting the mounting of VHDX files from untrusted sources and monitoring for the creation of unusual scheduled tasks that use administrative-sounding names but lack official digital signatures from Microsoft or verified vendors.
