Close Menu
EmpresernceMag
  • News
  • Us
  • World
  • Technology
  • Crypto
  • Money
    • Business and Market Watch
  • Career
  • Politics
  • Health/Wellness
    • Fitness
  • More
    • State of Women
    • Science/Tech
    • Relationships
    • Sports

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Women’s clothing store Cosette now open in the Fan

October 1, 2026

Russian state hackers use new RedFlick technique to push malware

October 1, 2026

Texas man arrested after allegedly planning attack on state Capitol: officials

October 1, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram Vimeo
EmpresernceMag
Login
  • News
  • Us
  • World
  • Technology
  • Crypto
  • Money
    • Business and Market Watch
  • Career
  • Politics
  • Health/Wellness
    • Fitness
  • More
    • State of Women
    • Science/Tech
    • Relationships
    • Sports
EmpresernceMag
  • News
  • Us
  • World
  • Technology
  • Crypto
  • Money
  • Career
  • Politics
  • Health/Wellness
  • More
Home » Russian state hackers use new RedFlick technique to push malware
Technology

Russian state hackers use new RedFlick technique to push malware

Tracy LeeBy Tracy LeeOctober 1, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Russian state hackers use new RedFlick technique to push malware
Share
Facebook Twitter LinkedIn Pinterest Email

Star Blizzard’s RedFlick Technique: A New Approach to Malware Deployment

Russian state hackers use new RedFlick technique to push malware

Overview of RedFlick

The Russian cyber-espionage group known as Star Blizzard has recently implemented a malware deployment strategy named “RedFlick.” This innovative approach primarily facilitates the deployment of their well-known CosmicPulse backdoor, providing a more automated method for executing attacks and reducing the need for user interaction.

Phishing for Initial Access

Research from Microsoft reveals that Star Blizzard has expanded its phishing efforts in 2026, streamlining the process of malware delivery. The initial phase of a RedFlick attack involves sending the target a phishing email, often disguised as an invitation. This is quickly followed by a second email containing a password-protected ZIP or RAR file.

Technical Execution of RedFlick

Inside the compressed file lies a VHDX virtual disk that contains an LNK file masquerading as a PDF. When the victim opens this deceptive file, it triggers a command in a concealed window while simultaneously displaying a legitimate-looking PDF to the unsuspecting user.

VHDX-based attack chain
VHDX-based attack chain
Source: Microsoft

Scheduled Tasks for Evasion

The executed commands lead to the download of an MSI installer, which sets up three scheduled tasks disguised as legitimate maintenance features:

  • Internet Quality Test Connection: Captures the network and computer name along with the username, allowing for remote DLL execution.
  • Network Configuration Manager: Configures Windows’ WebDAV functionality to facilitate remote web resource access.
  • System Health Monitor: Uses control.exe to implement a second-stage payload from a remote source.

These distinct scheduled tasks help the attackers avoid detection throughout the various phases of the operation.

The Second-Stage Payload

The next stage involves the deployment of a downloader known as NOROBOT and BAITSWITCH, delivered as a Control Panel applet (.cpl). This component is responsible for fetching and executing the CosmicPulse backdoor. Within the BAITSWITCH download, two ZIP archives are included—one containing a Python package that serves as a bootstrapper for CosmicPulse.

According to Microsoft, the bootstrapper retrieves an encrypted key from the system registry, decodes it using an embedded key, and subsequently uses that key to unlock the CosmicPulse payload.

RedFlick scheduled tasks
RedFlick scheduled tasks
Source: Microsoft

Current Threat Landscape

Experts from Microsoft assert that the capabilities of the backdoor remain consistent with previously reported functionalities, including executing attacker-supplied Python code, downloading and running files, and extracting documents from infected devices.

Notably, the RedFlick technique significantly reduces the effort required from victims, as activating the infection chain simply necessitates opening the malicious shortcut file. This marks a departure from Star Blizzard’s earlier ClickFix operations, which demanded more manual actions from users.

Targeted Campaigns and Recommendations

Since early 2026, Microsoft has documented at least 13 large-scale phishing campaigns attributed to Star Blizzard, affecting over 100 organizations, chiefly in the United States and the United Kingdom. The primary targets include Ukrainian entities and international organizations providing support to Ukraine.

Despite the evolution of its tactics, Star Blizzard continues to utilize impersonation of trusted contacts and relies on free email services to distribute phishing messages. To counteract these threats, Microsoft suggests:

  • Adopting phishing-resistant authentication methods.
  • Implementing Conditional Access policies.
  • Employing advanced email protection.
  • Independently verifying suspicious communications using established contact information.

In addition, utilizing endpoint detection and response (EDR) solutions in block mode can effectively prevent infections, intercepting malicious artifacts even if they bypass standard antivirus detection.

Conclusion

As cyber threats evolve, understanding and adapting to new tactics such as RedFlick is crucial for maintaining cybersecurity. Continuous vigilance and updated protective measures are essential in safeguarding information and infrastructure against sophisticated malware attacks.

article image

Join Mikko Hyppönen and leaders from various sectors at a digital summit to explore the implications of AI-speed attacks and how to enhance defensive strategies.

Save your seat!

Hackers malware Push RedFlick Russian State Technique
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleTexas man arrested after allegedly planning attack on state Capitol: officials
Next Article Women’s clothing store Cosette now open in the Fan
Tracy
Tracy Lee

Related Posts

Texas man arrested after allegedly planning attack on state Capitol: officials

October 1, 2026

Google Home update improves ‘Find my phone’ voice commands

October 1, 2026

Scalable decision-making for games of imperfect information

October 1, 2026

Nintendo Switch 2 and Switch update 23.0.1 out now, patch notes

October 1, 2026
Top Articles

Wicker Park Gym Incident: Two Women Accused of Credit Card Theft and Threats

August 30, 2025

Man Charged in Nighttime Kidnapping Attempts of Two Women

June 2, 2025

A Celebration of Love and Freedom

June 25, 2025

35% of Cornell undergraduate women reported having been sexually assaulted: Survey

September 30, 2026
Don't Miss
News

Women’s clothing store Cosette now open in the Fan

By Brenda YoungOctober 1, 20260

Ariel Richards, after years of experience in retail and fashion, has launched her own women’s…

Russian state hackers use new RedFlick technique to push malware

October 1, 2026

Texas man arrested after allegedly planning attack on state Capitol: officials

October 1, 2026

Current price of Ethereum for Sept. 30, 2026

October 1, 2026

Subscribe to Updates

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

About Us
About Us

Welcome to Empresence Mag, a news and lifestyle destination created to empower, inform, and inspire women around the world. Our mission is to provide a platform that highlights the stories, insights, and issues that matter most to women today.

Don't Miss

Women’s clothing store Cosette now open in the Fan

October 1, 2026

Russian state hackers use new RedFlick technique to push malware

October 1, 2026

Texas man arrested after allegedly planning attack on state Capitol: officials

October 1, 2026
New Comments
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 EmpresenceMag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Sign In or Register

    Welcome Back!

    Login to your account below.

    Lost password?