Star Blizzard's RedFlick technique delivers the CosmicPulse backdoor to 100+ organizations
By Sethu Satheesh · 6 Oct 2026 · 16 min read
Threat Actor: Star Blizzard (SEABORGIUM / COLDRIVER / Callisto) · Target: Ukraine-nexus NGOs, think tanks, governments and financial organizations (primarily US and UK)
Source: www.microsoft.com
Executive Summary
On September 29, 2026, Microsoft Threat Intelligence published technical analysis of a shift in the tradecraft of Star Blizzard, a Russian state threat actor the United States Cybersecurity and Infrastructure Security Agency (CISA) attributes as subordinate to the Russian Federal Security Service (FSB) Centre 18.12 Since January 2026, Microsoft has observed the actor move from narrowly targeted spear-phishing to large-scale initial-contact phishing, send from accounts created on compromised websites, and adopt a new malware-delivery technique Microsoft tracks as RedFlick. RedFlick is a delivery-and-persistence technique, not a payload; it uses Windows scheduled tasks to install the actor's custom Python backdoor, CosmicPulse.1
Microsoft counted at least 13 distinct large-scale phishing campaigns between January and August 2026, affecting over 100 organizations primarily in the United States and United Kingdom. Targeting centred on Ukrainian individuals and institutions, international NGOs, Western think tanks, governments, and financial organizations supporting Ukraine politically or financially.1 The infection flow begins with a phishing email; once a recipient responds, the actor sends a follow-up message carrying a password-protected RAR or ZIP archive, with the password supplied as an image in the email body. In the mid-January variant, the archive held a Virtual Hard Disk v2 (VHDX) that shipped a malicious LNK file disguised as a PDF alongside a hidden BAT script and a decoy PDF; opening the LNK spawned conhost.exe and cmd.exe, ran the BAT, and used SSH.exe with PermitLocalCommand to download and run a remotely hosted MSI that created scheduled tasks to fetch CosmicPulse.1
Star Blizzard — formerly tracked by Microsoft as SEABORGIUM and also known as Callisto Group, COLDRIVER, TA446, TAG-53, and BlueCharlie — is a long-running cyberespionage actor whose infrastructure and personnel have been the subject of prior public action: a December 2023 Five Eyes advisory and parallel US indictment and UK/US sanctions against two FSB-linked individuals, and an October 2024 joint Microsoft–Department of Justice seizure of 107 domains.2345 Microsoft frames RedFlick as a notable departure from the actor's 2025 ClickFix-based infection chains, which Google Threat Intelligence Group reported under the COLDCOPY name and which required victims to complete several manual steps; RedFlick, by contrast, requires a single user interaction.16
Why it matters: RedFlick is a case study in a state actor trading bespoke, high-touch targeting for scale while lowering the bar for victim interaction and leaning on trusted Windows binaries — conhost.exe, cmd.exe, ssh.exe, msiexec.exe, control.exe — to blend into normal activity. The reported scale also invites a precise reading: Microsoft said the activity affected more than 100 organizations and did not publish how many were breached, a distinction some downstream coverage collapses.17
Verification of Claims
-
Claim: RedFlick is a malware-delivery technique and CosmicPulse is the backdoor it deploys. → Verified → Microsoft's own analysis defines RedFlick as "a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse," a Python backdoor.1
-
Claim: Star Blizzard is subordinate to Russia's FSB Centre 18. → Partially verified → This is an assessed attribution. The December 2023 Five Eyes advisory assessed Star Blizzard is "almost certainly subordinate to" FSB Centre 18, and Microsoft repeats CISA's attribution; it is a confidence-graded government judgment, not a forensic certainty.12
-
Claim: The activity affected more than 100 organizations, primarily in the US and UK. → Partially verified → Microsoft states it "observed this activity affect over 100 organizations primarily in the United States and United Kingdom." Microsoft did not publish how many were compromised; The Hacker News noted at least one machine was infected but the number of breached organizations was not disclosed.17
-
Claim: Star Blizzard has abandoned ClickFix in favour of RedFlick. → Partially verified → Microsoft calls RedFlick "a notable departure from the actor's previous use of ClickFix-based infection chains" for delivering CosmicPulse, but also says it "continues to observe some previously reported Star Blizzard phishing techniques throughout 2026," including Evilginx spear-phishing. RedFlick supersedes ClickFix as the primary CosmicPulse-delivery chain; the actor has not dropped all prior tradecraft.18
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| October 2016 – October 2022 | Callisto Group / FSB Centre 18 | Period of the computer-intrusion conspiracy later charged by the US DOJ, targeting US and UK government, defence, and energy personnel | 3 |
| December 7, 2023 | CISA / NCSC / FBI / NSA / allied agencies | Joint advisory AA23-341a attributes Star Blizzard to FSB Centre 18; US DOJ indicts Ruslan Peretyatko and Andrey Korinets; US and UK sanction both | 234 |
| October 3, 2024 | US DOJ / Microsoft | Court-authorised seizure of 107 Star Blizzard domains (Microsoft 66 via civil action, DOJ 41) | 5 |
| October 2025 | Google Threat Intelligence Group | Reports Star Blizzard's COLDCOPY (ClickFix-based) malware delivery | 1 |
| Mid-January 2026 | Star Blizzard | First RedFlick campaigns target Ukr.net users with tax-audit lures; VHDX-based delivery of CosmicPulse observed | 1 |
| February 2026 | Star Blizzard | Fine-payment lures continue to target unidentified Ukraine persons | 1 |
| March 2026 | Star Blizzard | Targeting expands beyond Ukraine (IISS, CES, Atlantic Council lures); begins using accounts on compromised CPanel/WordPress sites; ProofPoint reports DarkSword iOS backdoor delivered via link | 1 |
| April 2026 | Star Blizzard | MSI installer shifts from one scheduled task to three ("Internet Quality Test Connection", "Network Configuration Manager", "System Health Monitor") | 1 |
| May 2026 | Star Blizzard | "Future of Peace Operations Forum" and "Future of Liberty Forum" lures target diplomatic bodies and a US think tank | 1 |
| June 2026 | Star Blizzard | MAMA Summit and Chatham House lures; Digital Security Lab Ukraine reports overlapping spear-phishing | 19 |
| July 2026 | Star Blizzard | USUBC roundtable and Kyiv water-shutdown lures; payloads hidden in PDFs behind the cAB magic header |
1 |
| Mid-August 2026 | Star Blizzard | "Payment Advice Note" lure with a unique ZIP per target; steganography used to conceal identifiers | 1 |
| September 29, 2026 | Microsoft Threat Intelligence | Publishes RedFlick technical analysis with IOCs and detections | 1 |
Attack Anatomy
Initial access
Star Blizzard makes initial contact with an email, usually without an attachment, impersonating a trusted political, diplomatic, academic, or organizational figure, often as an invitation to a closed-door event (T1566.002).1 For the higher-volume 2026 operations, the actor adopted a mass-mailing platform (tens to hundreds of messages per campaign) and created sender accounts on compromised CPanel- and WordPress-hosted websites, reusing one account name across multiple domains (T1584.004).1 When a recipient engages, the actor replies with a password-protected RAR or ZIP archive, the password supplied as an image in the email (T1566.001).1
Delivery and masquerading
In the mid-January 2026 variant, the archive contained a VHDX virtual disk — a container format that bypasses Mark-of-the-Web controls (T1553.005).1 The VHDX shipped a malicious LNK file disguised as a PDF (T1036.008), plus a hidden directory holding a BAT script and a legitimate decoy PDF.1 Opening the LNK launched conhost.exe in a hidden window and spawned cmd.exe to run the BAT (T1059.003).1 The BAT opened the decoy PDF and invoked SSH.exe with PermitLocalCommand enabled to download and execute a remotely hosted MSI installer (T1202, T1105).1 In the July 2026 chain, the LNK instead used conhost.exe and curl to download a PDF, after which a PowerShell payload searched the PDF for the magic header cAB, extracted the following 208 bytes of Base64, and executed the decoded command to fetch a further MSI (T1059.001, T1027.003, T1140).1
Installation and persistence
The MSI installer (T1218.007) created scheduled tasks for persistence (T1053.005). In the January campaign a single task used control.exe to download and run a CosmicPulse downloader compiled as a Control Panel applet (CPL) DLL (T1218.002).1 By April the installer created three tasks masquerading as legitimate network components (T1036.004): "Internet Quality Test Connection" beacons UTF-16/Base64-encoded host and user names to the C2 and can execute an attacker DLL via Control_RunDLL over a WebDAV UNC path; "Network Configuration Manager" prepares the WebDAV client used by the other tasks; and "System Health Monitor" uses control.exe to retrieve and execute the next stage from the hardcoded C2 (T1071.001).1
CosmicPulse downloader and backdoor
The CPL DLL downloader — publicly also tracked as NOROBOT or BAITSWITCH — downloads two ZIP files to disk and writes an encrypted AES key to the registry at HKEY_CURRENT_USER\Software\Classes\.mollis (T1112).1 One ZIP carries a Python 3.8 64-bit package and a bootstrapper; the bootstrapper reads the encrypted key, recovers it with an embedded key in AES-ECB mode, and decodes the CosmicPulse payload (also known as YESROBOT) from the second ZIP (T1140).1 CosmicPulse itself is a Python backdoor whose capabilities Microsoft says are unchanged from prior versions, with minor changes to evade signatures.1
Actions on objectives and exfiltration
The registration task exfiltrates basic host identifiers — network/computer name and username — to the C2 server, Base64-encoded (T1033, T1082, T1041), establishing the beachhead through which CosmicPulse operates for espionage collection consistent with the actor's longstanding objectives.1
Loading diagram...
Threat Actor Profile
Name: Star Blizzard (Microsoft; formerly SEABORGIUM) Aliases: Callisto Group, COLDRIVER (Google), TA446 (Proofpoint), TAG-53 (Recorded Future), BlueCharlie, and "Dancing Salome" (Kaspersky)23 Attribution confidence: Assessed. The December 2023 Five Eyes advisory assessed Star Blizzard is "almost certainly subordinate to" FSB Centre 18; Microsoft repeats CISA's attribution without a stated confidence qualifier.12 Motivation: State-directed cyberespionage — credential theft and intelligence collection against targets aligned with Russian strategic interests, particularly those supporting Ukraine.12
Star Blizzard has operated since at least 2017 and is known for patient, research-heavy spear-phishing against journalists, NGOs, think tanks, academics, and former intelligence and defence officials.8 The December 2023 US indictment charged Ruslan Aleksandrovich Peretyatko — an FSB Centre 18 officer — and Andrey Stanislavovich Korinets with a computer-intrusion conspiracy running from at least October 2016 to October 2022; material from compromised UK accounts was leaked ahead of the 2019 UK election.3 In October 2024, a Microsoft civil action and a parallel DOJ seizure took down 107 of the actor's domains.5 Through 2025 the actor delivered malware via ClickFix-style fake-CAPTCHA lures (Google's COLDCOPY), and in 2026 pivoted to RedFlick while retaining Evilginx-based credential phishing and continuing to use free-provider accounts such as Proton in targeted operations.16
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):
| ID | Technique |
|---|---|
| T1584.004 | Compromise Infrastructure: Server |
| T1566.001 | Phishing: Spearphishing Attachment |
| T1566.002 | Phishing: Spearphishing Link |
| T1204.002 | User Execution: Malicious File |
| T1553.005 | Subvert Trust Controls: Mark-of-the-Web Bypass |
| T1036.008 | Masquerading: Masquerade File Type |
| T1036.004 | Masquerading: Masquerade Task or Service |
| T1202 | Indirect Command Execution |
| T1059.003 | Command and Scripting Interpreter: Windows Command Shell |
| T1059.001 | Command and Scripting Interpreter: PowerShell |
| T1105 | Ingress Tool Transfer |
| T1218.007 | System Binary Proxy Execution: Msiexec |
| T1218.002 | System Binary Proxy Execution: Control Panel |
| T1053.005 | Scheduled Task/Job: Scheduled Task |
| T1027.003 | Obfuscated Files or Information: Steganography |
| T1140 | Deobfuscate/Decode Files or Information |
| T1112 | Modify Registry |
| T1071.001 | Application Layer Protocol: Web Protocols |
| T1033 | System Owner/User Discovery |
| T1082 | System Information Discovery |
| T1041 | Exfiltration Over C2 Channel |
OPSEC: Password-protected archives with the password sent as an image to defeat text-based scanning; VHDX containers and LNK-as-PDF masquerades to bypass Mark-of-the-Web and user suspicion; scheduled-task names impersonating Windows components; WebDAV-over-HTTP retrieval to avoid SMB; payloads concealed inside PDFs; steganography introduced in mid-August 2026; and compromised legitimate websites used for sender accounts.1
Technical Indicators
file_hashes_sha256:
- 9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b # Documents.zip, January campaign (Ukraine)
- 1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d # Documents.vhdx, January campaign (inside the ZIP above)
- 699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9 # Chatham_London_Conference_2026_Invitation.rar, June (pwd: LiveCrown8142)
- 24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7 # USUBC_Private_Executive_Roundtable_Webex.rar, July (pwd: LiteRaspberry9415)
- dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4 # Payment Advice Note.zip, August (pwd: BirdMouseCrab)
domains:
- etia[.]ca # RedFlick MSI installer host, January
- groy[.]cc # RedFlick MSI installer host, February
- muvb[.]net # RedFlick MSI installer host, February
- gliderrompercycl[.]com # CosmicPulse backdoor download
- divekickspolic[.]org # CosmicPulse backdoor download
- matjk[.]click # RedFlick MSI installer host, March
- bpdaersa[.]click # RedFlick MSI installer host, March
- stuseamandesilt[.]org # CosmicPulse backdoor download
- Itechx[.]tel # RedFlick MSI installer host, April
- guach[.]net # RedFlick PowerShell installer host, June
- ruten[.]observer # CosmicPulse downloader DLL host, June-July
- byveo[.]org # RedFlick PowerShell installer host, July
- secure-dns-hub[.]com # CosmicPulse downloader DLL host, July-current
- qumel[.]link # CosmicPulse downloader DLL host, July
- cyrna[.]top # RedFlick MSI installer host, August
- drasw[.]club # CosmicPulse downloader DLL host, August
ipv4:
- 103.245.231[.]248 # CosmicPulse downloader DLL host, January
- 2.57.241[.]246 # CosmicPulse downloader DLL host, February
- 89.125.209[.]168 # CosmicPulse downloader DLL host, February
- 103.245.231[.]79 # CosmicPulse downloader DLL host, March
- 45.84.59[.]66 # CosmicPulse downloader DLL host, April
- 103.160.59[.]97 # CosmicPulse downloader DLL host, July
registry_persistence:
- 'HKEY_CURRENT_USER\Software\Classes\.mollis' # encrypted AES key for CosmicPulse
scheduled_task_names:
- 'Internet Quality Test Connection' # beaconing + dynamic DLL execution
- 'Network Configuration Manager' # WebDAV client support
- 'System Health Monitor' # CosmicPulse downloader execution
host_binaries_abused:
- conhost.exe
- cmd.exe
- ssh.exe # invoked with PermitLocalCommand=yes, LocalCommand=cmd.exe
- curl.exe
- msiexec.exe
- control.exe
note: >
All indicators are from Microsoft Threat Intelligence's September 29, 2026 report.
Archive passwords are listed as reported indicators (actor-supplied, delivered as
images in the phishing emails), not as credentials to any live service. Microsoft
warns that file names and infrastructure rotate between campaigns.Legal and Regulatory Response
No new law-enforcement action, indictment, or sanction tied specifically to the 2026 RedFlick campaigns had been published as of October 6, 2026; Microsoft states it directly notifies targeted and compromised customers.1 The actor is, however, the subject of substantial prior public action. On December 7, 2023, CISA, the UK NCSC, the FBI, the NSA, and allied agencies published advisory AA23-341a attributing Star Blizzard to FSB Centre 18; the US Department of Justice unsealed an indictment of FSB Centre 18 officer Ruslan Aleksandrovich Peretyatko and Andrey Stanislavovich Korinets for a global computer-intrusion conspiracy; and the US Treasury's OFAC and the UK sanctioned both men.234 On October 3, 2024, a Microsoft civil action and a parallel DOJ seizure took down 107 domains used by the actor (66 seized by Microsoft, 41 by the DOJ), with the supporting affidavit describing the group as a criminal proxy for an operational unit within FSB Centre 18.5 Charges remain allegations; the named individuals are outside US and UK jurisdiction and have not been tried.3
Impact Assessment
- Confirmed: Microsoft observed at least 13 distinct large-scale phishing campaigns between January and August 2026 using the RedFlick technique to deliver CosmicPulse.1
- Reported, not independently confirmed: The activity affected over 100 organizations, primarily in the US and UK. This is Microsoft's own telemetry; the figure counts organizations observed affected, not confirmed breaches, and Microsoft did not disclose how many were compromised.17
- Reported, not independently confirmed: A March 2026 campaign delivered the DarkSword iOS backdoor via a link, as reported by Proofpoint; a mid-August 2026 campaign used steganography.1
- Unknown: The number of successful CosmicPulse installations, the volume or nature of data exfiltrated, and the identities of affected organizations. Microsoft published no victim count beyond "over 100 organizations" affected.1
Lessons and Defensive Recommendations
For SOC/defenders:
- Hunt for
conhost.exelaunchingcurl, and forssh.exeinvoked withPermitLocalCommand=yesandLocalCommand=cmd.exe— both are anomalous on most endpoints and were used by this actor in 2026.1 - Alert on creation of scheduled tasks named "Internet Quality Test Connection", "Network Configuration Manager", or "System Health Monitor", and on writes to
HKEY_CURRENT_USER\Software\Classes\.mollis.1 - Treat
control.exeloading a CPL from a remote or WebDAV UNC path, andmsiexecinstalling MSIs fetched byssh/curl, as high-signal; block or monitor outbound SSH to non-business destinations.1 - Load the Microsoft IOC set (hashes, 16 domains, 6 IPs) into network and web-session detections, treating infrastructure as rotating.1
For email and platform teams:
- Password-protected archives whose password arrives as an image evade text-based scanning; detonate or quarantine such attachments and flag archives containing VHDX/ISO or LNK files disguised as documents. Enable Mark-of-the-Web enforcement so container formats do not launder downloaded content.1
- Watch for sender display names that reference a real person or organization while the registered domain does not match (the organization appears only in the local part of the address), a persistent Star Blizzard tell.1
For leadership (at-risk sectors — Ukraine-nexus NGOs, think tanks, government, finance):
- Deploy phishing-resistant authentication and conditional access; this actor's core objective remains credential theft and account access, and it continues parallel Evilginx operations alongside RedFlick.18
- Assume the "100+ organizations affected" figure understates exposure for a reader's sector rather than overstates it: the number is Microsoft telemetry, not a confirmed breach count, and targeting is broad across Ukraine-aligned policy and finance bodies.17
Sources
Footnotes
-
Microsoft Threat Intelligence — Star Blizzard refines phishing and malware delivery with the RedFlick technique — September 29, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47 ↩48 ↩49 ↩50 ↩51
-
CISA / NCSC / FBI / NSA and allied agencies — Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns (AA23-341A) — December 7, 2023 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
US Department of Justice, Office of Public Affairs — Two Russian Nationals Working with Russia's Federal Security Service Charged with Global Computer Intrusion Campaign — December 7, 2023 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
US Department of the Treasury, Office of Foreign Assets Control — Recent Actions: cyber-related designations of Peretyatko and Korinets — December 7, 2023 ↩ ↩2 ↩3
-
US Department of Justice, Office of Public Affairs — Justice Department Disrupts Russian Intelligence Spear-Phishing Efforts — October 3, 2024 ↩ ↩2 ↩3 ↩4
-
Google Threat Intelligence Group — COLDRIVER Uses New Malware to Steal Documents From Western Targets and NGOs — 2025 ↩ ↩2
-
The Hacker News — Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor — September 2026 ↩ ↩2 ↩3 ↩4
-
Dark Reading — Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net — September 30, 2026 ↩ ↩2 ↩3
-
Digital Security Lab Ukraine — Spearphishing via fake URC 2026 invitations targets Ukrainian CSOs — 2026 ↩
Related Research
Attackers put a request for nuclear weapon instructions inside a malicious script, not to attack anyone, but so an AI reviewing the code would refuse to read further. The defender's safety guardrail becomes the evasion.
Anthropic's September threat report describes a Midnight Blizzard-linked operator running eight AI workflows — phishing, hotel Wi-Fi hijack, malware evasion — against 24 targets in Ukraine and Europe. Microsoft's CaptiveCrunch report, from the other side, lists four of the same domains.
A Russian web developer extradited from Georgia faces trial over a 2023–25 operation that bought search ads impersonating banks, harvested 5,000+ logins and 2FA codes on cloned pages, and tried to wire $5.58 million from one Atlanta company in a day. The mule LLC was registered in Georgia two months