malware
Published 2026-09-29
Verified 2026-09-30

Star Blizzard (FSB Centre 18): RedFlick scheduled-task delivery of CosmicPulse Python backdoor — 100+ orgs since Jan 2026 (Microsoft)

Microsoft Threat Intelligence (29 September 2026): Russian state actor Star Blizzard (aka COLDRIVER / Callisto; CISA-attributed FSB Centre 18) refined phishing and malware delivery with RedFlick — MSI/LNK chains that create Windows scheduled tasks to deploy custom Python backdoor CosmicPulse (downloader also reported as NOROBOT/BAITSWITCH), replacing 2025 ClickFix-heavy tradecraft. Since January 2026 Microsoft observed ≥13 larger-scale campaigns (tens–hundreds of emails each) plus conventional spear-phish; activity affected over 100 organizations, primarily Ukraine-linked individuals/institutions and international NGOs, think tanks, governments and financial institutions supporting Ukraine (mostly US/UK in THN amplify). Lures: fake event/conference invites (e.g. Chatham House / Atlantic Council themes), Ukr.net tax/fine notices, Kyiv utility themes; reply then password-protected RAR/ZIP (password in image) with LNK-as-PDF → MSI → tasks (names mimicking Internet Quality Test / Network Configuration Manager / System Health Monitor) using WebDAV/control.exe paths. Since March: phishing from accounts on compromised WordPress/cPanel sites. One March campaign linked (medium confidence) to DarkSword iPhone exploit kit instead of Windows backdoor. Microsoft ships hunting queries and Defender detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse; at least one C2 domain still active at publication. Wire: THN 29 Sep. Primary: Microsoft Security Blog.

Product
Windows endpoints (Star Blizzard RedFlick → CosmicPulse Python backdoor); phishing via compromised webmail
Versions
n/a (espionage malware TTPs; apply Microsoft IoCs/hunting queries from 29 Sep blog; Defender detections Trojan:Script/RedFlick, Backdoor:Python/CosmicPulse)
Exploited in Australia?
unknown
Patch to
No CVE. Prioritise gov/NGO/think-tank/finance staff on Ukraine policy: block password-protected archives from unsolicited invite threads; alert on new scheduled tasks mimicking network-health names and WebDAV/control.exe remote CPL loads; hunt Microsoft IoCs (including live domains noted in blog); enable cloud mailbox rules against reply-then-archive patterns; keep OS/EDR current. AU: Five Eyes historical Star Blizzard advisories still relevant — treat as espionage credential/access risk, not ransomware.

Primary: Microsoft Threat Intelligence — Star Blizzard / RedFlick / CosmicPulse (29 Sep 2026) · Vendor: Microsoft Security Blog (primary) · The Hacker News — Star Blizzard fake event invites → CosmicPulse (29 Sep 2026)

tech identity network