INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Russian State Hackers Employ New RedFlick Malware Technique

| 2026-09-30 20:34 CRITICAL HIGH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor, according to extracted tactical telemetry. This technique was first observed on September 30, 2026, and has since targeted Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially. The attacks begin with a phishing email, followed by a second message containing a password-protected ZIP or RAR archive. Microsoft researchers note that Star Blizzard expanded its phishing operations and streamlined malware delivery in 2026, using tactics such as impersonating trusted contacts or organizations to deliver phishing messages. To mitigate these threats, companies are advised to use phishing-resistant authentication, Conditional Access policies, email protection, and independently verify suspicious messages through established contact details.
Technical Mitigations AI-generated
• Implement phishing-resistant authentication and Conditional Access policies: Companies can use solutions like Microsoft's Azure Active Directory (AAD) to protect users from phishing attacks. AAD provides features such as multi-factor authentication, conditional access controls, and threat intelligence feeds. • Use email protection and independently verify suspicious messages: Organizations should implement email security solutions that detect and block malicious emails before they reach the user's inbox. Additionally, employees can be trained to verify suspicious messages through established contact details or by contacting IT support directly. • Deploy endpoint detection and response (EDR) solutions in block mode: EDR solutions like Microsoft Defender Advanced Threat Protection (ATP) can help prevent infections by blocking malicious artifacts even if they manage to evade traditional security controls. Block mode ensures that the solution scans all files, folders, and registry keys for potential threats. • Monitor system logs and network traffic for suspicious activity: Organizations should monitor their system logs and network traffic for signs of RedFlick malware installation, such as unusual scheduled tasks or command executions in hidden windows. This can help detect and respond to attacks more quickly. • Implement a robust security information and event management (SIEM) system: A SIEM system like Microsoft's Azure Sentinel can collect and analyze log data from various sources, providing real-time insights into potential threats. It can also alert administrators to suspicious activity and provide recommendations for remediation.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

co•••••.exe
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎October 2025
Star Blizzard, a Russian state actor, has been using the T1059.006 Python backdoor to execute attacker-supplied code and download/run files or retrieve documents from infected systems since October 2025.
tactic T1059.006 - Python
organisation Google
‎2026/09/30
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor.
threat_actor Star Blizzard
organisation RedFlick
organisation CosmicPulse
organisation Microsoft
organisation ClickFix
organisation WhatsApp
victims 100 organizations
organisation StarBlizzard
organisation Conditional Access
infrastructure Windows
organisation Network Configuration
organisation Windows’ WebDAV
organisation VHDX
organisation LNK
organisation PDF
organisation MSI
organisation DLL
organisation BAITSWITCH
organisation AES
organisation EDR
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
victims
100
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources
BleepingComputer 2026-09-30
Mastodon BleepingComputer 2026-09-30