Star Blizzard Deploys RedFlick in 100+ Org Cyber Espionage Wave

•By CyberNewsAI Admin•VERIFIED INTEL
Cinematic threat dashboard visual analyzing Russia's Star Blizzard RedFlick spear-phishing campaign and CosmicPulse backdoor delivery

SOC Briefing Summary :: Executive Key Takeaways

  • [01]Russian state-sponsored threat group Star Blizzard (FSB Center 18 / COLDRIVER) targeted more than 100 Western organizations across the U.S., U.K., and Europe with 13+ large-scale spear-phishing campaigns since January 2026.
  • [02]The group evolved from multi-step ClickFix lures to 'RedFlick'—a low-friction infection chain deploying malicious LNK files, deceptive Scheduled Tasks, and control.exe proxying to drop the CosmicPulse Python backdoor.
  • [03]Audit Windows environments for masqueraded scheduled tasks ('Internet Quality Test Connection'), restrict outbound WebDAV/SSH connections, and deploy phishing-resistant FIDO2 MFA.
SHARE INTEL:Reddit

Executive Summary

Microsoft Threat Intelligence has exposed a sophisticated, multi-stage cyber espionage offensive orchestrated by Star Blizzard (tracked externally as COLDRIVER, SEABORGIUM, TA446, and attributed by Five Eyes intelligence agencies to Center 18 of Russia's Federal Security Service [FSB]). Since January 2026, the advanced persistent threat (APT) group has launched at least 13 coordinated spear-phishing waves targeting over 100 organizations—predominantly government bodies, defense contractors, international NGOs, and policy think tanks focused on Ukraine.

The campaign introduces a notable tradecraft evolution dubbed RedFlick by Microsoft. Moving away from the high-interaction 'ClickFix' fake CAPTCHA schemes utilized throughout 2025, RedFlick streamlines victim interaction into a single-click infection chain. Threat operators initiate conversational dialogue from compromised third-party WordPress and cPanel email systems before delivering password-protected archives with passwords embedded inside images.

Once opened, disguised Windows Shortcut (.LNK) files establish persistence via deceptive Windows Scheduled Tasks that mimic legitimate operating system health monitors. The chain abuses trusted Windows binaries (control.exe) and WebDAV shares to deploy CosmicPulse, a stealthy Python backdoor, while dynamically routing targeted iOS mobile devices to the DarkSword exploit kit.

Technical Vulnerability Analysis & Attack Chain

Attack Chain Flow
// Attack Chain Flow

Stage 1: Trusted Dialogue & Event Ingress

  • Infrastructural Pivoting: Star Blizzard abandoned its historical reliance on free webmail providers (such as Proton Mail and consumer Microsoft accounts), shifting entirely to legitimate corporate email servers compromised across commercial WordPress and cPanel environments. This allows phishing messages to cleanly pass SPF, DKIM, and DMARC reputation scoring.
  • Conversational Social Engineering: Attackers initiate contact posing as organizers from high-profile institutions, including Chatham House, the Atlantic Council, and the Ukraine Recovery Conference (URC 2026). The introductory email contains no hyperlinks, tracking pixels, or attachments, successfully evading inbound Secure Email Gateway (SEG) sandboxes.
  • Targeted Segmentation: In early 2026, initial lures targeted Ukrainian civil society organizations and users of the Ukr.net mail service with fake tax audit and penalty notices. As operations progressed, lures shifted to diplomatic summit registrations, Kyiv municipal water shutdown advisories, and international financial payment notices.

Stage 2: Encrypted Archive & LNK Execution

  • Sandbox Evasion via Image Passwords: Once a target responds to confirm attendance or verify identity, Star Blizzard replies with a password-protected ZIP or RAR archive. The decryption password is not provided in plaintext body text; instead, it is rendered as an embedded image within the email body, preventing automated email security scanners from extracting and detonating the payload.
  • Disguised LNK Shortcut: The archive contains a single .LNK file disguised with a native Adobe Acrobat PDF icon and formatted with double extensions (e.g., Event_Invitation_Agenda.pdf.lnk).
  • Payload Fetching Mechanics: Execution of the LNK triggers obfuscated command-line utilities. In January iterations, the script executed native Windows ssh.exe client binaries to securely retrieve an MSI package from attacker-controlled SSH servers. In July variants, the LNK executed background PowerShell commands to extract Base64-encoded strings embedded within a secondary decoy PDF.

Stage 3: Deceptive Scheduled Tasks Persistence

The retrieved Windows Installer (.MSI) package executes silently, registering three persistent Windows Scheduled Tasks crafted with deceptive names designed to blend into standard enterprise network telemetry:

  1. Internet Quality Test Connection: Executes periodically to gather network adapter status, machine hostname, and logged-in user credentials, transmitting initial system beacons to Star Blizzard command-and-control (C2) servers.
  2. Network Configuration Manager: Initializes the Windows WebDAV Client Redirector service (davhttp), mounting a remote WebDAV directory hosted on attacker-controlled infrastructure (secure-dns-hub[.]com).
  3. System Health Monitor: Acts as the local execution trigger, using native Windows administrative scheduling to invoke the staged payload from the mounted WebDAV directory.

Stage 4: Control Panel Proxy Execution & Loader Staging

  • Living-off-the-Land (LOLBin) Abuse: Rather than invoking cmd.exe or raw PowerShell to load the backdoor, the System Health Monitor scheduled task calls control.exe (the native Windows Control Panel binary).
  • Control Panel Applet (`.CPL`) Proxying: control.exe is directed to execute a remote or cached Control Panel applet disguised as a legitimate configuration component. Because control.exe is a trusted, digitally signed Microsoft operating system binary, endpoint detection and response (EDR) heuristics rarely flag the initial execution context.
  • NOROBOT / BAITSWITCH Loader: The Control Panel item executes the NOROBOT (also tracked by researchers as BAITSWITCH) staged downloader. NOROBOT performs anti-analysis checks, detects virtual machine hypervisor artifacts, and decrypts the primary payload directly into memory.

Stage 5: CosmicPulse Backdoor & DarkSword Mobile Fork

  • CosmicPulse Python Backdoor: NOROBOT drops and executes CosmicPulse, a modular Python-based backdoor. CosmicPulse establishes persistent C2 communication over encrypted HTTPS with secure-dns-hub[.]com (resolving to 103.160.59[.]97), allowing Star Blizzard operators to:
    • Harvest local system credentials and browser session cookies.
    • Execute arbitrary shellcode and secondary PowerShell commands.
    • Enumerate Active Directory shares, policy documents, and diplomatic communications.
  • DarkSword iOS Exploit Fork: Telemetry corroborated by Proofpoint and Trellix revealed an alternative mobile targeting path. When targets opened invitation links on mobile devices, Star Blizzard redirected them away from the Windows chain to landing pages hosting DarkSword—an exploit kit chaining six vulnerabilities across WebKit and the iOS kernel to install spyware on unpatched iPhones prior to iOS 26.3.

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Resource DevelopmentT1584.004Compromise Infrastructure: ServerCompromising legitimate WordPress and cPanel accounts to send authenticated phishing
Initial AccessT1566.001Phishing: Spearphishing AttachmentDelivering password-protected ZIP/RAR archives following conversational social engineering
ExecutionT1204.002User Execution: Malicious FileVictim clicks disguised .LNK file with PDF icon within uncompressed archive
Defense EvasionT1027.013Obfuscated/Encrypted Files: Password ProtectionImage-embedded passwords in email bodies preventing automated gateway sandbox decryption
PersistenceT1053.005Scheduled Task/Job: Scheduled TaskRegistering 'Internet Quality Test Connection' and 'Network Configuration Manager' tasks
Defense EvasionT1036.005Masquerading: Match Legitimate Name or LocationNaming malicious scheduled tasks and CPL applets after Windows system health utilities
Defense EvasionT1218.002System Binary Proxy Execution: Control PanelAbusing control.exe to execute malicious applets hosted on remote WebDAV shares
Lateral MovementT1021.006Remote Services: Windows Remote Management / WebDAVUtilizing Windows WebDAV Redirector to stage and execute remote binaries
Command and ControlT1071.001Application Layer Protocol: Web ProtocolsCosmicPulse backdoor beaconing to C2 infrastructure over encrypted HTTPS
CollectionT1005Data from Local SystemHarvesting policy documents, saved credentials, and session tokens for exfiltration

Threat Actor Profile & Campaign Attribution

Threat Actor: Star Blizzard (Aliases: COLDRIVER, SEABORGIUM, Callisto Group, TA446).

Attribution & Intelligence Background:

  • FSB Center 18 Nexus: In December 2023, the U.S. Department of Justice, the U.K. National Cyber Security Centre (NCSC), and intelligence agencies across Five Eyes officially attributed Star Blizzard's operations to officers serving within Center 18 of Russia's Federal Security Service (FSB).
  • Mission Objectives: Unlike Russian military intelligence (GRU) units known for disruptive wipers (Sandworm), Star Blizzard operates primarily as a strategic cyber espionage and intelligence-gathering service. Their long-term mandate centers on penetrating foreign policy think tanks, defense ministries, NATO delegations, academic institutions, and NGOs involved in formulating Western policy on Ukraine and Eastern Europe.
  • Historical Tradecraft Trajectory:
    • 2022–2023: Extensive credential harvesting campaigns utilizing Evilginx reverse-proxy infrastructure to bypass standard SMS and app-based multi-factor authentication (MFA).
    • 2024–2025: Introduction of ClickFix fake CAPTCHA and browser error lures that tricked targets into copying and executing encoded PowerShell commands.
    • 2026 (RedFlick): Transition to lower-friction, stealthier infection chains pairing hijacked commercial hosting infrastructure, Living-off-the-Land execution via control.exe, and multi-platform weaponization across Windows (CosmicPulse) and iOS (DarkSword).

Detection & SOC Mitigation Playbook

1. Patch & Workaround Guidance

  • Audit & Remove Rogue Scheduled Tasks: Query endpoints across the enterprise for scheduled tasks containing the specific strings Internet Quality Test Connection, Network Configuration Manager, or System Health Monitor.
  • Deploy Mobile Security Patches: Mandate immediate updates to iOS 26.3 or later on all corporate and BYOD mobile devices managing organizational email, completely neutralizing the six vulnerabilities chained by the DarkSword exploit kit. Enable iOS Lockdown Mode for high-risk personnel.
  • Enforce FIDO2 Phishing-Resistant MFA: Upgrade authentication from push-based or SMS OTPs to hardware security keys (YubiKeys) or Windows Hello for Business. FIDO2 authentication cryptographically binds credentials to the originating domain, preventing session hijacking via reverse-proxy phishing frameworks (e.g., Evilginx).
  • Attack Surface Reduction (ASR) Rules: Enable the following Microsoft Defender ASR rules across all Windows endpoints:
    • Block executable files from running unless they meet a prevalence, age, or trusted list criterion (01443614-cd74-433a-b99e-2ecdc07bfc25)
    • Block execution of potentially obfuscated scripts (5beb8661-ae78-454c-ba65-69f23c4e40a5)
    • Block process creations originating from PSExec and WMI commands (d1e49aac-8f56-4280-b9ba-993a6d77406c)

2. Network & Perimeter Defenses

  • Restrict Outbound WebDAV & SMB: Block outbound TCP port 445 (SMB) and disable the Windows WebClient service (WebClient) via Group Policy (GPO) across all workstations not requiring WebDAV functionality.
  • Restrict Outbound SSH Connections: Deny outbound TCP port 22 connections from standard corporate workstations to the internet, restricting SSH egress exclusively to dedicated developer bastion jump-hosts.
  • Ingress Domain & Header Inspection: Inspect incoming email headers where display names match recognized diplomatic or think tank domains, but envelope sender domains originate from commercial web hosting providers (WordPress/cPanel).

3. Endpoint Detection & Hunting Query

QUERY / DETECTION_RULE
SIGMA / YAML
title: Star Blizzard RedFlick Scheduled Task and Control Panel Proxy Execution
id: 8b2f1c4e-9d3a-4f7b-b5a8-2e4f1a6c8d0e
status: experimental
date: 2026/09/29
author: CyberNewsAI Threat Intelligence
description: Detects Star Blizzard RedFlick persistent scheduled tasks and control.exe LOLBin execution indicative of CosmicPulse staging
references:
  - https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
  - https://cybernewsai.com/blog/star-blizzard-redflick-phishing-cosmicpulse-backdoor
logsource:
  category: process_creation
  product: windows
detection:
  selection_tasks:
    Image|endswith: '\schtasks.exe'
    CommandLine|contains:
      - 'Internet Quality Test Connection'
      - 'Network Configuration Manager'
      - 'System Health Monitor'
  selection_control:
    Image|endswith: '\control.exe'
    CommandLine|contains:
      - '.cpl'
      - 'http'
      - '\\'
  selection_msi:
    Image|endswith: '\msiexec.exe'
    CommandLine|contains|all:
      - '/i'
      - '/q'
  condition: selection_tasks or (selection_control and selection_msi)
level: critical
tags:
  - attack.persistence
  - attack.t1053.005
  - attack.defense_evasion
  - attack.t1218.002
  - attack.g0140
falsepositives:
  - Legitimate enterprise deployment scripts utilizing control.exe applets (extremely uncommon in modern environments)
QUERY / DETECTION_RULE
SENTINEL / KQL
// Microsoft Sentinel / Defender XDR - Hunting for Star Blizzard RedFlick Infection Artifacts
// Detects RedFlick scheduled task creation, WebDAV execution, and CosmicPulse Python staging
DeviceProcessEvents
| where Timestamp >= ago(30d)
| where (FileName =~ "schtasks.exe" and ProcessCommandLine has_any (
    "Internet Quality Test Connection",
    "Network Configuration Manager",
    "System Health Monitor"
))
or (FileName =~ "control.exe" and ProcessCommandLine matches regex @"(?i)(http|\\\\|\.cpl)")
or (InitiatingProcessFileName =~ "control.exe" and FileName =~ "python.exe")
| project Timestamp, DeviceName, ActionType, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, AccountName
| sort by Timestamp desc

Network Indicators & Command-and-Control (C2)

IndicatorTypeContext / Association
secure-dns-hub[.]comDomainPrimary C2 server for RedFlick campaigns & CosmicPulse backdoor
103.160.59[.]97IPv4 AddressInfrastructure hosting secure-dns-hub[.]com and WebDAV staging
Trojan:Script/RedFlickDefender SignatureMicrosoft Defender detection family for RedFlick LNK/scripting stage
Backdoor:Python/CosmicPulseDefender SignatureMicrosoft Defender detection for primary post-exploitation Python implant

File System & Task Telemetry

Telemetry ArtifactCategoryOperational Function
Internet Quality Test ConnectionWindows Scheduled TaskGathers host telemetry and beacons to C2 infrastructure
Network Configuration ManagerWindows Scheduled TaskMounts WebDAV share pointing to remote attacker server
System Health MonitorWindows Scheduled TaskInvokes control.exe to execute staged CPL downloader
.LNK (Disguised as .PDF)Dropper FileShortcut triggering silent MSI download via SSH or Base64 script
NOROBOT / BAITSWITCHMalware StagerDownloader applet performing anti-VM checks and deploying CosmicPulse
DarkSwordExploit KitChained iOS zero-day toolkit targeting mobile device respondents
Indicators of Compromise (IOCs)
11 Identified
domainsecure-dns-hub.com
ip103.160.59.97
scheduled_taskInternet Quality Test Connection
scheduled_taskNetwork Configuration Manager
scheduled_taskSystem Health Monitor
malwareCosmicPulse
malwareRedFlick
malwareNOROBOT
malwareBAITSWITCH
exploit_kitDarkSword
threat_actorStar Blizzard (FSB Center 18)
// EVERGREEN RELIC // P1 INCIDENT
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light mockup

Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light

“Because nation-state APTs strictly observe your weekend plans.”

Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.

Direct Armory Fulfillment$25
ACQUIRE RELIC
Fast US Shipping (2-4 Days)• 1-Click Apple / Google Pay
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE