RedFlick delivers the CosmicPulse backdoor via scheduled tasks
Assessment
Microsoft Threat Intelligence defines RedFlick as 'a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse,' a Python backdoor. RedFlick is the delivery-and-persistence technique; CosmicPulse (publicly also NOROBOT/BAITSWITCH downloader and YESROBOT payload) is the backdoor. Conflating the two, or calling RedFlick a backdoor, reverses the primary source.
Where this claim appeared
Microsoft Threat Intelligence · 2026-09-29
https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/What “Verified” means
Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.
5 of 5 · rating scale
Assessed in
Star Blizzard's RedFlick technique delivers the CosmicPulse backdoor to 100+ organizationsThink this assessment is wrong? Report an error.