Russian Cyber Unit Star Blizzard Deploys New “RedFlick” Method to Install CosmicPulse Backdoor
Security researchers have identified a fresh intrusion technique employed by the Russian state‑linked hacking group known as Star Blizzard, which they have labeled “RedFlick.” The method is being used to drop the group’s longstanding CosmicPulse backdoor onto victim systems, expanding the toolkit available to the actors behind the operation.
According to the analysis, RedFlick leverages a multi‑stage process that begins with a seemingly innocuous file or script, often masquerading as a legitimate utility. Once executed, the payload initiates a covert download of the CosmicPulse component, bypassing common security controls by exploiting trusted system processes and obfuscating network traffic.
Star Blizzard, a group that has been linked to Russian intelligence services for several years, has previously been associated with a range of espionage‑focused malware families. The introduction of RedFlick marks a shift toward more sophisticated delivery mechanisms, reflecting the group’s ongoing effort to stay ahead of defensive measures and maintain persistent access within high‑value networks.
The discovery was first reported by BleepingComputer, which cited technical details shared by independent security labs. Analysts say the new technique complicates detection because it blends malicious actions with normal system behavior, making it harder for signature‑based tools to flag the activity. The move underscores a broader trend among state‑sponsored actors to adopt layered, stealthy approaches that reduce the likelihood of early exposure.
Cybersecurity firms are urging organizations to adopt a defense‑in‑depth strategy that includes behavioral monitoring, strict application whitelisting, and regular audits of privileged accounts. Sharing indicators of compromise (IOCs) related to RedFlick and the CosmicPulse payload across industry information‑sharing platforms is also being emphasized as a critical step in limiting the technique’s spread.
While the full scope of RedFlick’s deployment remains under investigation, experts expect the method to appear in future campaigns targeting sectors that are traditionally of interest to Russian intelligence, such as government, defense, and critical infrastructure. Continued vigilance and rapid response to emerging threat‑intel will be essential in mitigating the risks posed by this evolving intrusion vector.
Comments (0)
Be the first to comment.
Join the discussion