Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Russian State Actor Star Blizzard Deploys “RedFlick” Malware Delivery Chain via Phishing

Star Blizzard’s RedFlick technique uses a password‑protected archive and a disguised shortcut to install the CosmicPulse backdoor. The attack highlights the need for robust security‑awareness and execution‑control monitoring to satisfy audit‑ready control objectives.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Russian State Actor Star Blizzard Deploys “RedFlick” Malware Delivery Chain via Phishing

What Happened — Star Blizzard introduced a new delivery method called RedFlick that begins with a phishing email containing a password‑protected archive. The archive holds a VHDX virtual disk with an LNK file masquerading as a PDF; opening it launches a hidden command that installs scheduled‑task components and ultimately drops the CosmicPulse backdoor via the NOROBOT/BAITSWITCH downloader.

Why It Matters for Trust & Control Assurance

  • The technique exploits the human element and weak attachment‑handling policies—exactly the scenario a continuous security‑awareness program is built to detect, document, and remediate.
  • Evidence of phishing‑email triage, attachment scanning, and execution‑prevention controls provides a defensible audit trail for identity‑access and user‑behavior controls.
  • Mapping this attack to the “identity and access control” objective shows how automated monitoring of scheduled‑task creation and privileged command execution can surface the chain early, supporting continuous control‑assurance.

Who Is Affected — Enterprises across finance, technology, healthcare, and government that rely on Windows workstations and accept email attachments from external parties.

Recommended Actions

  • Enforce strict attachment‑type filtering and sandbox analysis for archives, especially password‑protected ZIP/RAR files.
  • Deploy endpoint detection that flags creation of scheduled tasks with suspicious names or locations.
  • Refresh security‑awareness training to highlight LNK‑file masquerading and the need to verify PDF sources before opening.

Technical Notes – Attack vector: phishing email → password‑protected archive → VHDX with LNK → hidden command → MSI installer → three scheduled tasks (Internet Quality Test Connection, Network Configuration Manager, System Health Monitor) → downloader (NOROBOT/BAITSWITCH) → CosmicPulse backdoor. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/russian-state-hackers-use-new-redflick-technique-to-push-malware/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →