Russian Threat Actor Deploys New RedFlick Malware Delivery Method

Russian state-sponsored group Star Blizzard has adopted a new malware installation technique called RedFlick to distribute its CosmicPulse backdoor, streamlining attacks through VHDX virtual disk files hidden in password-protected archives. The attack chain uses multiple scheduled tasks with distinct functions to evade detection while downloading and executing the final payload through a Control Panel applet downloader. This represents an evolution of Star Blizzard's tactics to reduce victim interaction and further automate its phishing and malware deployment operations.
Star Blizzard has refined its attack methodology by leveraging virtual disk technology to obscure malicious files within encrypted archives, making initial detection more difficult. The infection sequence employs a tiered approach where each scheduled task operates independently, complicating security response and allowing the attacker to maintain persistence across multiple system components. This compartmentalization strategy represents a deliberate evolution toward reducing reliance on user compliance.
Since 2026 began, Microsoft has documented over a dozen separate phishing campaigns reaching more than 100 organizations. The geographic focus extends beyond Eastern European targets to encompass international NGOs, financial institutions, and governmental bodies with demonstrated support for Ukraine. The group's persistent use of free email services as distribution channels suggests limited defensive barriers at that infrastructure level remain effective for their purposes.
The RedFlick technique could significantly impact organizational security planning, particularly for entities handling sensitive geopolitical or financial information. The automated infection chain may prove more difficult for traditional email filtering to intercept, potentially increasing successful breach rates. Organizations lacking robust endpoint detection or multi-factor authentication systems could face elevated risk, while the technique's effectiveness may incentivize other threat actors to adopt similar methods, broadening the threat landscape across critical infrastructure and international institutions.