Russian State Hackers Deploy New 'RedFlick' Malware Installation Tactic

Star Blizzard group automates attacks using virtual disk files and scheduled tasks to deliver CosmicPulse backdoor

By LineZotpaper
Published
Read Time2 min
Microsoft researchers have identified a new malware delivery technique, dubbed RedFlick, used by the Russian state actor Star Blizzard to deploy its signature CosmicPulse backdoor. The method involves phishing emails leading to password-protected archives containing VHDX virtual disk files, allowing the group to automate attacks and reduce victim interaction.

According to Microsoft, Star Blizzard—active since at least 2017—has adopted RedFlick as its latest infection vector. The attack begins with a phishing email, such as a fake invitation, followed by a second message containing a password-protected ZIP or RAR archive.

Inside the archive is a VHDX virtual disk file that contains an LNK file disguised as a PDF. When the victim opens the LNK file, it executes a command in a hidden window while displaying a decoy PDF. The command downloads and runs an MSI installer that creates three scheduled tasks, each named to pose as legitimate Windows maintenance components:

  • Internet Quality Test Connection sends the computer and network name to attackers and can execute a remote DLL.
  • Network Configuration Manager prepares Windows' WebDAV functionality to access remote web resources via file-style paths.
  • System Health Monitor uses control.exe to execute a remotely hosted next-stage payload.

This multi-stage approach helps the attacker evade detection by breaking the attack into separate steps. The next-stage payload, a downloader known as NOROBOT or BAITSWITCH, arrives as a Control Panel applet (.cpl) and fetches the CosmicPulse backdoor.

BAITSWITCH downloads two ZIP archives—one containing Python 3.8 64-bit and a Python bootstrapper. The bootstrapper reads an encrypted key from the registry, recovers it with an embedded AES-ECB key, and decodes the CosmicPulse payload.

The RedFlick technique is not a novel cybersecurity method, but it represents a streamlined delivery approach for Star Blizzard. The group has previously explored other delivery avenues such as ClickFix and WhatsApp, and continues to develop new malware families.

§

Analysis

Why This Matters

  • Organizations targeted by Russian state-linked espionage—particularly diplomats, defense contractors, and government agencies—face a more automated and harder-to-detect infection vector.
  • The use of VHDX virtual disks and scheduled tasks makes each stage appear legitimate, increasing the chance of successful compromise.
  • Microsoft's warning signals a broader evolution in state-backed phishing operations, where attackers reduce reliance on manual steps.

Background

Star Blizzard (also tracked as SEABORGIUM, APT29) is a Russian state-sponsored hacking group linked to the country's intelligence services. It has historically targeted NATO countries, think tanks, and government officials through spear-phishing campaigns. Over the years, the group has shifted tactics, using techniques like ClickFix (fake CAPTCHA prompts) and WhatsApp messages to deliver payloads. RedFlick is its latest adaptation, leveraging virtual disk files—a format often overlooked by security tools.

Key Perspectives

Microsoft Security Team: The researchers emphasize that RedFlick automates delivery and reduces victim interaction, allowing the group to scale operations while making detection harder. The use of multiple scheduled tasks with benign-sounding names is designed to evade endpoint defenses. Target Organizations: High-value targets such as diplomats and military personnel must remain vigilant against multi-stage phishing attacks, especially those using password-protected archives and VHDX files. Cybersecurity Community: Defenders should monitor for VHDX files arriving via email, unusual scheduled tasks named after system components, and unexpected WebDAV configurations.

What to Watch

  • Whether Microsoft and other security vendors add detection signatures for the RedFlick-related artifacts (VHDX attachments, specific scheduled task names).
  • If other threat actors adopt or modify the VHDX-based delivery method.
  • Future Microsoft or law enforcement actions targeting the infrastructure used in these campaigns.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.