Star Blizzard's RedFlick Campaign Targets Ukraine-Linked Organizations
Microsoft disclosed on September 29, 2026, that the Russian state-sponsored threat actor Star Blizzard has overhauled its phishing tradecraft, retiring its ClickFix-based lures in favor of a new, lower-interaction delivery method Microsoft calls RedFlick. Since January 2026, the group has used RedFlick across at least 13 large campaigns — sending anywhere from tens to hundreds of phishing emails per wave — to plant a custom Python backdoor named CosmicPulse on the Windows machines of more than 100 organizations, the majority located in the United States and United Kingdom. Microsoft, which is highly confident Star Blizzard operates as a subordinate of Center 18 of Russia's Federal Security Service (FSB), said the group has also been tracked under the names SEABORGIUM, Callisto Group, TA446, and COLDRIVER. The campaigns overwhelmingly target people and institutions connected to Ukraine, and Microsoft confirmed at least one successful infection.
| Attribute | Value |
|---|---|
| Threat actor | Star Blizzard |
| Also tracked as | SEABORGIUM, Callisto Group, TA446, COLDRIVER |
| Attribution | Subordinate to FSB Center 18 (per Microsoft/CISA) |
| New infection chain | RedFlick (replaces prior ClickFix lures) |
| Payload | CosmicPulse — custom Python backdoor |
| Downloaders used | NoroBot, BaitSwitch |
| Campaign window | January 2026 – present |
| Scale | 100+ organizations, at least 13 campaigns, tens to hundreds of emails per wave |
| Primary regions targeted | United States, United Kingdom |
| Targeted sectors | Ukrainian individuals/institutions, NGOs, think tanks, governments, diplomatic bodies, financial institutions backing Ukraine |
| Confirmed impact | At least one successful CosmicPulse infection |
| Microsoft detections | Trojan:Script/RedFlick, Backdoor:Python/CosmicPulse |
| Disclosure date | September 29, 2026 |
From ClickFix to RedFlick
Through 2025, Star Blizzard relied on ClickFix — fake CAPTCHA pages that trick a target into manually copy-pasting and running a malicious command themselves. That approach required multiple deliberate actions from the victim, giving defenders more opportunities to interrupt the chain. RedFlick collapses that into effectively a single click: once a target opens the malicious attachment, scheduled tasks are silently provisioned in the background and the CosmicPulse backdoor is installed with no further victim action required.
How the RedFlick Infection Chain Evolved
Microsoft tracked three distinct iterations of RedFlick between January and July 2026, each adding obfuscation:
January — the VHDX baseline. Phishing emails carried a malicious Virtual Hard Disk (VHDX) container. Inside sat the RedFlick payload: a shortcut (LNK) file disguised as a PDF. Clicking it opened a decoy document while a background script ran silently, fetching an MSI installer from attacker infrastructure. The MSI configured scheduled tasks for persistence and launched the NoroBot or BaitSwitch downloader, which in turn retrieved and installed CosmicPulse.
April — added persistence and reconnaissance. Star Blizzard began using three RedFlick scheduled tasks disguised with innocuous names — "Internet Quality Test Connection," "Network Configuration Manager," and "System Health Monitor" — to blend into normal Windows activity. RedFlick installers from this period also created scheduled tasks that collected basic host information, enabled WebDAV (Web Distributed Authoring and Versioning) access, and retrieved the components needed to complete the CosmicPulse install.
July — layered archive obfuscation. The group added a further wrapper, nesting a password-protected RAR archive inside a ZIP file. The enclosed shortcut downloaded a PDF containing encoded data, which a PowerShell script extracted and executed to retrieve the next-stage MSI installer — an extra layer intended to defeat automated scanning of the initial attachment.
The CosmicPulse Backdoor
CosmicPulse is Star Blizzard's signature payload across all three RedFlick variants — a Python-based backdoor delivered as the final stage after the NoroBot or BaitSwitch downloader runs. Microsoft's detection for the implant, Backdoor:Python/CosmicPulse, reflects its role as the group's persistent foothold on compromised hosts once the scheduled-task persistence layer is in place.
Living Off the Land, Not Exploiting
A key detail for defenders: RedFlick is not built on a software vulnerability. Every stage relies on components already present on a stock Windows install — Scheduled Tasks, control.exe, WebDAV, SSH, curl, and PowerShell. There is nothing to patch; the chain succeeds through social engineering plus the misuse of legitimate, signed system utilities, which makes application-control and behavioral detection more important than vulnerability management for catching it.
Infrastructure and Targeting
Star Blizzard has also shifted its sending infrastructure. Earlier campaigns relied mostly on free consumer email services such as Proton and Microsoft accounts; Microsoft said it now has high confidence the group is using accounts on compromised WordPress and cPanel websites to mass-mail its lures, impersonating Ukrainian authorities, reputable think tanks, or NGOs, and sometimes spoofing messages to appear as though they originate from within the target's own organization. One command-and-control domain tied to the campaign remained active as of Microsoft's September 29 publication.
Impact Assessment
| Impact Area | Description |
|---|---|
| Reduced attacker friction | RedFlick needs only one victim click versus ClickFix's multi-step manual execution, raising the odds of successful compromise |
| Detection difficulty | Reliance on built-in Windows tools (Scheduled Tasks, PowerShell, WebDAV, curl, SSH) blends malicious activity into normal admin noise |
| Sector exposure | NGOs, think tanks, diplomatic bodies, and financial institutions supporting Ukraine face sustained, targeted espionage risk |
| Confirmed compromise | At least one organization was successfully infected with CosmicPulse, confirming real-world effectiveness, not just attempted delivery |
| Infrastructure trust erosion | Abuse of hijacked WordPress/cPanel accounts as sending infrastructure complicates reputation- and domain-based email filtering |
| Active infrastructure | At least one Star Blizzard command-and-control domain remained live at time of disclosure, posing continued risk to unpatched detections |
Recommendations
For Windows Administrators and IT Teams
- Audit Scheduled Tasks for unfamiliar entries, especially ones masquerading with generic names like "Internet Quality Test Connection," "Network Configuration Manager," or "System Health Monitor."
- Restrict or monitor WebDAV client activity, since RedFlick installers use it to retrieve second-stage components.
- Apply attachment controls that block or sandbox VHDX, LNK, and nested archive (RAR-in-ZIP) attachments arriving via email, particularly from external or first-contact senders.
- Enforce PowerShell constrained-language mode and script-block logging to catch the decode-and-execute step used in the July variant.
For Security Operations and Threat Hunters
- Deploy Microsoft's published indicators and the three Defender XDR hunting queries for RedFlick and CosmicPulse activity.
- Hunt for the detection signatures Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse across endpoint telemetry.
- Watch for MSI installers launched from user-writable temp paths shortly after a decoy PDF is opened — a consistent chain pattern across all three RedFlick variants.
- Flag inbound mail from WordPress- or cPanel-hosted domains impersonating NGOs, think tanks, or government bodies for additional scrutiny.
For Individuals at NGOs, Think Tanks, and Ukraine-Linked Organizations
- Inspect sender addresses closely: Microsoft noted that Star Blizzard lures often show a real person's name and a legitimate-sounding organization in the display name, but the organization appears only in the username portion before the "@" — not in the actual registered domain.
- Treat unsolicited event invitations, especially those requesting a password-protected archive be opened, as high-risk until verified through a separate channel.
- Never enter commands into a Run dialog or terminal based on instructions from an email or webpage, and report suspected RedFlick-style lures to your security team immediately.
Key Takeaways
- Star Blizzard, an FSB Center 18-linked Russian APT also known as SEABORGIUM, Callisto Group, TA446, and COLDRIVER, has shifted from ClickFix to a new RedFlick infection chain since January 2026.
- RedFlick has been used in at least 13 campaigns against 100+ organizations, mostly in the US and UK, targeting Ukrainian individuals, NGOs, think tanks, governments, and financial institutions backing Ukraine.
- The chain evolved through three iterations — VHDX-based delivery in January, disguised scheduled-task persistence and WebDAV use in April, and layered RAR-in-ZIP archive obfuscation in July.
- The final payload, CosmicPulse, is a custom Python backdoor delivered via the NoroBot or BaitSwitch downloaders; Microsoft confirmed at least one successful infection.
- RedFlick exploits no vulnerability — it relies entirely on legitimate Windows components (Scheduled Tasks, PowerShell, WebDAV, curl, SSH), making detection and configuration hygiene the primary defense.
- Star Blizzard now mass-mails through compromised WordPress and cPanel accounts rather than free consumer email services, and at least one related command-and-control domain was still active as of disclosure.