According to Microsoft, Star Blizzard—active since at least 2017—has adopted RedFlick as its latest infection vector. The attack begins with a phishing email, such as a fake invitation, followed by a second message containing a password-protected ZIP or RAR archive.
Inside the archive is a VHDX virtual disk file that contains an LNK file disguised as a PDF. When the victim opens the LNK file, it executes a command in a hidden window while displaying a decoy PDF. The command downloads and runs an MSI installer that creates three scheduled tasks, each named to pose as legitimate Windows maintenance components:
- Internet Quality Test Connection sends the computer and network name to attackers and can execute a remote DLL.
- Network Configuration Manager prepares Windows' WebDAV functionality to access remote web resources via file-style paths.
- System Health Monitor uses control.exe to execute a remotely hosted next-stage payload.
This multi-stage approach helps the attacker evade detection by breaking the attack into separate steps. The next-stage payload, a downloader known as NOROBOT or BAITSWITCH, arrives as a Control Panel applet (.cpl) and fetches the CosmicPulse backdoor.
BAITSWITCH downloads two ZIP archives—one containing Python 3.8 64-bit and a Python bootstrapper. The bootstrapper reads an encrypted key from the registry, recovers it with an embedded AES-ECB key, and decodes the CosmicPulse payload.
The RedFlick technique is not a novel cybersecurity method, but it represents a streamlined delivery approach for Star Blizzard. The group has previously explored other delivery avenues such as ClickFix and WhatsApp, and continues to develop new malware families.