RedFlick Campaign Leverages Scheduled Tasks and Encrypted Archives to Deploy CosmicPulse Backdoor
Microsoft’s threat‑intelligence team has identified a new intrusion method used by the Russian‑linked cyber‑espionage group known as Star Blizzard. The technique, dubbed RedFlick, combines scheduled‑task creation with password‑protected archive files to install a backdoor identified as CosmicPulse, expanding the group’s activity in 2026.
RedFlick begins with a classic phishing email that carries a compressed archive as an attachment. The archive is encrypted with a password that is sent to the recipient through a separate channel, such as a follow‑up message or a legitimate‑looking web request. Once the victim supplies the password and extracts the payload, a Windows scheduled task is automatically created to launch the malicious executable with elevated privileges, ensuring persistence even after a system reboot.
The Star Blizzard group, which U.S. Cybersecurity and Infrastructure Security Agency (CISA) attributes to Russia’s federal security services, has a history of targeting diplomatic, governmental and critical‑infrastructure entities. Earlier campaigns employed a range of tools, but the introduction of RedFlick marks a shift toward more layered delivery mechanisms that blend social engineering with native Windows functionality.
CosmicPulse, the payload delivered by RedFlick, is designed to provide long‑term remote access, enabling operators to move laterally across networks, exfiltrate sensitive data and deploy additional modules. Its use of scheduled tasks makes detection harder for conventional antivirus solutions, while the encrypted archive bypasses many email‑gateway scanners that cannot inspect password‑protected files.
In response, Microsoft has issued technical guidance urging organizations to scrutinize newly created scheduled tasks, enforce strict controls on archive handling, and verify the legitimacy of any password‑exchange communications. CISA has also added RedFlick to its catalog of known adversary techniques, recommending multi‑factor authentication, network segmentation and timely patching as mitigations.
Analysts expect that Star Blizzard will continue to refine its tactics, potentially incorporating other native Windows features to further obscure malicious activity. Ongoing collaboration between private security firms and government agencies will be essential to surface such evolving threats before they achieve broader impact.
Comments (0)
Be the first to comment.
Join the discussion