MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-30 · via BleepingComputer

Russian Threat Actor Deploys New RedFlick Malware Delivery Method

Image via BleepingComputer
Image via BleepingComputer

Russian state-sponsored group Star Blizzard has adopted a new malware installation technique called RedFlick to distribute its CosmicPulse backdoor, streamlining attacks through VHDX virtual disk files hidden in password-protected archives. The attack chain uses multiple scheduled tasks with distinct functions to evade detection while downloading and executing the final payload through a Control Panel applet downloader. This represents an evolution of Star Blizzard's tactics to reduce victim interaction and further automate its phishing and malware deployment operations.

Expanded Detail

Star Blizzard has refined its attack methodology by leveraging virtual disk technology to obscure malicious files within encrypted archives, making initial detection more difficult. The infection sequence employs a tiered approach where each scheduled task operates independently, complicating security response and allowing the attacker to maintain persistence across multiple system components. This compartmentalization strategy represents a deliberate evolution toward reducing reliance on user compliance.

Since 2026 began, Microsoft has documented over a dozen separate phishing campaigns reaching more than 100 organizations. The geographic focus extends beyond Eastern European targets to encompass international NGOs, financial institutions, and governmental bodies with demonstrated support for Ukraine. The group's persistent use of free email services as distribution channels suggests limited defensive barriers at that infrastructure level remain effective for their purposes.

Context

The RedFlick technique could significantly impact organizational security planning, particularly for entities handling sensitive geopolitical or financial information. The automated infection chain may prove more difficult for traditional email filtering to intercept, potentially increasing successful breach rates. Organizations lacking robust endpoint detection or multi-factor authentication systems could face elevated risk, while the technique's effectiveness may incentivize other threat actors to adopt similar methods, broadening the threat landscape across critical infrastructure and international institutions.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Russian state hackers use new RedFlick technique to push malware.” Browse more stories.