ThreatPaper
Verified

RedFlick delivers the CosmicPulse backdoor via scheduled tasks

Assessment

Microsoft Threat Intelligence defines RedFlick as 'a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse,' a Python backdoor. RedFlick is the delivery-and-persistence technique; CosmicPulse (publicly also NOROBOT/BAITSWITCH downloader and YESROBOT payload) is the backdoor. Conflating the two, or calling RedFlick a backdoor, reverses the primary source.

Where this claim appeared

Microsoft Threat Intelligence · 2026-09-29

https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Star Blizzard's RedFlick technique delivers the CosmicPulse backdoor to 100+ organizations

Think this assessment is wrong? Report an error.