Skip to content

Security1 publisher2 min readPublished

Star Blizzard's RedFlick technique plants the CosmicPulse backdoor after one click

Star Blizzard's one-click RedFlick chain has affected over 100 organizations since January, mostly in the US and UK, Microsoft says. Scheduled tasks now install the group's CosmicPulse backdoor, so hunting for it moves from the user's actions to the task scheduler.

The Watch · Security desk

Illustration accompanying Star Blizzard's RedFlick technique plants the CosmicPulse backdoor after one click

What happened

  • Star Blizzard's earlier ClickFix chains needed victims to complete several actions before the CosmicPulse backdoor could be installed.
  • Its 2026 phishing campaigns range between tens and hundreds of emails each, a volume Microsoft had not seen from the group before.
  • The group now creates accounts on compromised websites and sends its phishing emails from them.
  • Targets include Ukrainian individuals and institutions plus NGOs, think tanks, governments and financial institutions that have backed Ukraine politically or financially.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision ClickFix and credential-phishing detections for this group stay in place, because Microsoft still sees older Star Blizzard techniques in 2026; scheduled-task hunting is an addition to them.
  • constraint Phishing sent from accounts on compromised legitimate sites is harder to stop with sender-domain reputation, so more of the defence falls to the endpoint after the click.
  • precedent Microsoft's September 29 post is the kind of public exposure that has preceded the group's past overhauls, so its indicators are likely to have a short useful life.
  • exposure Organizations with no Ukraine policy or funding link can treat this as low priority, since Microsoft says the victim set matches the group's long-running targets.

A detection tuned to ClickFix looks for a victim working through a sequence of steps [3]. RedFlick leaves one interaction to see [4]. After that, a set of scheduled tasks deploys CosmicPulse, and Microsoft says the technique helps the group evade detection [2]. Task creation is the step the actor cannot drop, because the install runs through it [2].

Microsoft's overview does not describe the interaction itself or name the tasks. It also does not say how many of the affected organizations were compromised and how many were only targeted [6]. The company says the post includes indicators of compromise, detections and hunting guidance for RedFlick activity, and that it notifies targeted or compromised customers directly [15].

The older pattern was slower. In Microsoft's 2023-2024 reporting, the actor opened email contact with a target first. It then sent a follow-up link to credential-theft infrastructure, while posing as known political or diplomatic figures [14]. Microsoft's assessment is that mass phishing plus a shorter chain likely lets Star Blizzard reach more targets, evade detection and compromise more of them [5].

CISA attributes Star Blizzard to Centre 18 of Russia's FSB [10]. Microsoft says the group overhauls its methods periodically, often after its campaigns are publicly exposed [11]. The changes in this report followed Google Threat Intelligence Group's October 2025 report on the group's COLDCOPY malware [12]. Microsoft first saw the new tradecraft in January 2026 [1], about three months after that report [1]. It published on September 29, 2026 [16], about nine months into the activity [2].

What to watch

  • Whether Star Blizzard changes its delivery method again after Microsoft's September 29 post, as it did in the months after Google's October 2025 COLDCOPY report.
  • Figures from Microsoft or CISA separating compromised organizations from those only targeted by RedFlick.
  • A CISA advisory on RedFlick or CosmicPulse; the agency already attributes Star Blizzard to FSB Centre 18.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories