Star Blizzard Deploys RedFlick in 100+ Org Cyber Espionage Wave

SOC Briefing Summary :: Executive Key Takeaways
- [01]Russian state-sponsored threat group Star Blizzard (FSB Center 18 / COLDRIVER) targeted more than 100 Western organizations across the U.S., U.K., and Europe with 13+ large-scale spear-phishing campaigns since January 2026.
- [02]The group evolved from multi-step ClickFix lures to 'RedFlick'—a low-friction infection chain deploying malicious LNK files, deceptive Scheduled Tasks, and control.exe proxying to drop the CosmicPulse Python backdoor.
- [03]Audit Windows environments for masqueraded scheduled tasks ('Internet Quality Test Connection'), restrict outbound WebDAV/SSH connections, and deploy phishing-resistant FIDO2 MFA.
Executive Summary
Microsoft Threat Intelligence has exposed a sophisticated, multi-stage cyber espionage offensive orchestrated by Star Blizzard (tracked externally as COLDRIVER, SEABORGIUM, TA446, and attributed by Five Eyes intelligence agencies to Center 18 of Russia's Federal Security Service [FSB]). Since January 2026, the advanced persistent threat (APT) group has launched at least 13 coordinated spear-phishing waves targeting over 100 organizations—predominantly government bodies, defense contractors, international NGOs, and policy think tanks focused on Ukraine.
The campaign introduces a notable tradecraft evolution dubbed RedFlick by Microsoft. Moving away from the high-interaction 'ClickFix' fake CAPTCHA schemes utilized throughout 2025, RedFlick streamlines victim interaction into a single-click infection chain. Threat operators initiate conversational dialogue from compromised third-party WordPress and cPanel email systems before delivering password-protected archives with passwords embedded inside images.
Once opened, disguised Windows Shortcut (.LNK) files establish persistence via deceptive Windows Scheduled Tasks that mimic legitimate operating system health monitors. The chain abuses trusted Windows binaries (control.exe) and WebDAV shares to deploy CosmicPulse, a stealthy Python backdoor, while dynamically routing targeted iOS mobile devices to the DarkSword exploit kit.
Technical Vulnerability Analysis & Attack Chain

Stage 1: Trusted Dialogue & Event Ingress
- Infrastructural Pivoting: Star Blizzard abandoned its historical reliance on free webmail providers (such as Proton Mail and consumer Microsoft accounts), shifting entirely to legitimate corporate email servers compromised across commercial WordPress and cPanel environments. This allows phishing messages to cleanly pass SPF, DKIM, and DMARC reputation scoring.
- Conversational Social Engineering: Attackers initiate contact posing as organizers from high-profile institutions, including Chatham House, the Atlantic Council, and the Ukraine Recovery Conference (URC 2026). The introductory email contains no hyperlinks, tracking pixels, or attachments, successfully evading inbound Secure Email Gateway (SEG) sandboxes.
- Targeted Segmentation: In early 2026, initial lures targeted Ukrainian civil society organizations and users of the Ukr.net mail service with fake tax audit and penalty notices. As operations progressed, lures shifted to diplomatic summit registrations, Kyiv municipal water shutdown advisories, and international financial payment notices.
Stage 2: Encrypted Archive & LNK Execution
- Sandbox Evasion via Image Passwords: Once a target responds to confirm attendance or verify identity, Star Blizzard replies with a password-protected ZIP or RAR archive. The decryption password is not provided in plaintext body text; instead, it is rendered as an embedded image within the email body, preventing automated email security scanners from extracting and detonating the payload.
- Disguised LNK Shortcut: The archive contains a single
.LNKfile disguised with a native Adobe Acrobat PDF icon and formatted with double extensions (e.g.,Event_Invitation_Agenda.pdf.lnk). - Payload Fetching Mechanics: Execution of the LNK triggers obfuscated command-line utilities. In January iterations, the script executed native Windows
ssh.execlient binaries to securely retrieve an MSI package from attacker-controlled SSH servers. In July variants, the LNK executed background PowerShell commands to extract Base64-encoded strings embedded within a secondary decoy PDF.
Stage 3: Deceptive Scheduled Tasks Persistence
The retrieved Windows Installer (.MSI) package executes silently, registering three persistent Windows Scheduled Tasks crafted with deceptive names designed to blend into standard enterprise network telemetry:
Internet Quality Test Connection: Executes periodically to gather network adapter status, machine hostname, and logged-in user credentials, transmitting initial system beacons to Star Blizzard command-and-control (C2) servers.Network Configuration Manager: Initializes the Windows WebDAV Client Redirector service (davhttp), mounting a remote WebDAV directory hosted on attacker-controlled infrastructure (secure-dns-hub[.]com).System Health Monitor: Acts as the local execution trigger, using native Windows administrative scheduling to invoke the staged payload from the mounted WebDAV directory.
Stage 4: Control Panel Proxy Execution & Loader Staging
- Living-off-the-Land (LOLBin) Abuse: Rather than invoking
cmd.exeor raw PowerShell to load the backdoor, theSystem Health Monitorscheduled task callscontrol.exe(the native Windows Control Panel binary). - Control Panel Applet (`.CPL`) Proxying:
control.exeis directed to execute a remote or cached Control Panel applet disguised as a legitimate configuration component. Becausecontrol.exeis a trusted, digitally signed Microsoft operating system binary, endpoint detection and response (EDR) heuristics rarely flag the initial execution context. - NOROBOT / BAITSWITCH Loader: The Control Panel item executes the NOROBOT (also tracked by researchers as BAITSWITCH) staged downloader. NOROBOT performs anti-analysis checks, detects virtual machine hypervisor artifacts, and decrypts the primary payload directly into memory.
Stage 5: CosmicPulse Backdoor & DarkSword Mobile Fork
- CosmicPulse Python Backdoor: NOROBOT drops and executes CosmicPulse, a modular Python-based backdoor. CosmicPulse establishes persistent C2 communication over encrypted HTTPS with
secure-dns-hub[.]com(resolving to103.160.59[.]97), allowing Star Blizzard operators to:- Harvest local system credentials and browser session cookies.
- Execute arbitrary shellcode and secondary PowerShell commands.
- Enumerate Active Directory shares, policy documents, and diplomatic communications.
- DarkSword iOS Exploit Fork: Telemetry corroborated by Proofpoint and Trellix revealed an alternative mobile targeting path. When targets opened invitation links on mobile devices, Star Blizzard redirected them away from the Windows chain to landing pages hosting DarkSword—an exploit kit chaining six vulnerabilities across WebKit and the iOS kernel to install spyware on unpatched iPhones prior to iOS 26.3.
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Resource Development | T1584.004 | Compromise Infrastructure: Server | Compromising legitimate WordPress and cPanel accounts to send authenticated phishing |
| Initial Access | T1566.001 | Phishing: Spearphishing Attachment | Delivering password-protected ZIP/RAR archives following conversational social engineering |
| Execution | T1204.002 | User Execution: Malicious File | Victim clicks disguised .LNK file with PDF icon within uncompressed archive |
| Defense Evasion | T1027.013 | Obfuscated/Encrypted Files: Password Protection | Image-embedded passwords in email bodies preventing automated gateway sandbox decryption |
| Persistence | T1053.005 | Scheduled Task/Job: Scheduled Task | Registering 'Internet Quality Test Connection' and 'Network Configuration Manager' tasks |
| Defense Evasion | T1036.005 | Masquerading: Match Legitimate Name or Location | Naming malicious scheduled tasks and CPL applets after Windows system health utilities |
| Defense Evasion | T1218.002 | System Binary Proxy Execution: Control Panel | Abusing control.exe to execute malicious applets hosted on remote WebDAV shares |
| Lateral Movement | T1021.006 | Remote Services: Windows Remote Management / WebDAV | Utilizing Windows WebDAV Redirector to stage and execute remote binaries |
| Command and Control | T1071.001 | Application Layer Protocol: Web Protocols | CosmicPulse backdoor beaconing to C2 infrastructure over encrypted HTTPS |
| Collection | T1005 | Data from Local System | Harvesting policy documents, saved credentials, and session tokens for exfiltration |
Threat Actor Profile & Campaign Attribution
Threat Actor: Star Blizzard (Aliases: COLDRIVER, SEABORGIUM, Callisto Group, TA446).
Attribution & Intelligence Background:
- FSB Center 18 Nexus: In December 2023, the U.S. Department of Justice, the U.K. National Cyber Security Centre (NCSC), and intelligence agencies across Five Eyes officially attributed Star Blizzard's operations to officers serving within Center 18 of Russia's Federal Security Service (FSB).
- Mission Objectives: Unlike Russian military intelligence (GRU) units known for disruptive wipers (Sandworm), Star Blizzard operates primarily as a strategic cyber espionage and intelligence-gathering service. Their long-term mandate centers on penetrating foreign policy think tanks, defense ministries, NATO delegations, academic institutions, and NGOs involved in formulating Western policy on Ukraine and Eastern Europe.
- Historical Tradecraft Trajectory:
- 2022–2023: Extensive credential harvesting campaigns utilizing Evilginx reverse-proxy infrastructure to bypass standard SMS and app-based multi-factor authentication (MFA).
- 2024–2025: Introduction of ClickFix fake CAPTCHA and browser error lures that tricked targets into copying and executing encoded PowerShell commands.
- 2026 (RedFlick): Transition to lower-friction, stealthier infection chains pairing hijacked commercial hosting infrastructure, Living-off-the-Land execution via
control.exe, and multi-platform weaponization across Windows (CosmicPulse) and iOS (DarkSword).
Detection & SOC Mitigation Playbook
1. Patch & Workaround Guidance
- Audit & Remove Rogue Scheduled Tasks: Query endpoints across the enterprise for scheduled tasks containing the specific strings
Internet Quality Test Connection,Network Configuration Manager, orSystem Health Monitor. - Deploy Mobile Security Patches: Mandate immediate updates to iOS 26.3 or later on all corporate and BYOD mobile devices managing organizational email, completely neutralizing the six vulnerabilities chained by the DarkSword exploit kit. Enable iOS Lockdown Mode for high-risk personnel.
- Enforce FIDO2 Phishing-Resistant MFA: Upgrade authentication from push-based or SMS OTPs to hardware security keys (YubiKeys) or Windows Hello for Business. FIDO2 authentication cryptographically binds credentials to the originating domain, preventing session hijacking via reverse-proxy phishing frameworks (e.g., Evilginx).
- Attack Surface Reduction (ASR) Rules: Enable the following Microsoft Defender ASR rules across all Windows endpoints:
Block executable files from running unless they meet a prevalence, age, or trusted list criterion(01443614-cd74-433a-b99e-2ecdc07bfc25)Block execution of potentially obfuscated scripts(5beb8661-ae78-454c-ba65-69f23c4e40a5)Block process creations originating from PSExec and WMI commands(d1e49aac-8f56-4280-b9ba-993a6d77406c)
2. Network & Perimeter Defenses
- Restrict Outbound WebDAV & SMB: Block outbound TCP port 445 (SMB) and disable the Windows WebClient service (
WebClient) via Group Policy (GPO) across all workstations not requiring WebDAV functionality. - Restrict Outbound SSH Connections: Deny outbound TCP port 22 connections from standard corporate workstations to the internet, restricting SSH egress exclusively to dedicated developer bastion jump-hosts.
- Ingress Domain & Header Inspection: Inspect incoming email headers where display names match recognized diplomatic or think tank domains, but envelope sender domains originate from commercial web hosting providers (WordPress/cPanel).
3. Endpoint Detection & Hunting Query
title: Star Blizzard RedFlick Scheduled Task and Control Panel Proxy Execution
id: 8b2f1c4e-9d3a-4f7b-b5a8-2e4f1a6c8d0e
status: experimental
date: 2026/09/29
author: CyberNewsAI Threat Intelligence
description: Detects Star Blizzard RedFlick persistent scheduled tasks and control.exe LOLBin execution indicative of CosmicPulse staging
references:
- https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
- https://cybernewsai.com/blog/star-blizzard-redflick-phishing-cosmicpulse-backdoor
logsource:
category: process_creation
product: windows
detection:
selection_tasks:
Image|endswith: '\schtasks.exe'
CommandLine|contains:
- 'Internet Quality Test Connection'
- 'Network Configuration Manager'
- 'System Health Monitor'
selection_control:
Image|endswith: '\control.exe'
CommandLine|contains:
- '.cpl'
- 'http'
- '\\'
selection_msi:
Image|endswith: '\msiexec.exe'
CommandLine|contains|all:
- '/i'
- '/q'
condition: selection_tasks or (selection_control and selection_msi)
level: critical
tags:
- attack.persistence
- attack.t1053.005
- attack.defense_evasion
- attack.t1218.002
- attack.g0140
falsepositives:
- Legitimate enterprise deployment scripts utilizing control.exe applets (extremely uncommon in modern environments)// Microsoft Sentinel / Defender XDR - Hunting for Star Blizzard RedFlick Infection Artifacts
// Detects RedFlick scheduled task creation, WebDAV execution, and CosmicPulse Python staging
DeviceProcessEvents
| where Timestamp >= ago(30d)
| where (FileName =~ "schtasks.exe" and ProcessCommandLine has_any (
"Internet Quality Test Connection",
"Network Configuration Manager",
"System Health Monitor"
))
or (FileName =~ "control.exe" and ProcessCommandLine matches regex @"(?i)(http|\\\\|\.cpl)")
or (InitiatingProcessFileName =~ "control.exe" and FileName =~ "python.exe")
| project Timestamp, DeviceName, ActionType, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, AccountName
| sort by Timestamp descNetwork Indicators & Command-and-Control (C2)
| Indicator | Type | Context / Association |
|---|---|---|
| secure-dns-hub[.]com | Domain | Primary C2 server for RedFlick campaigns & CosmicPulse backdoor |
| 103.160.59[.]97 | IPv4 Address | Infrastructure hosting secure-dns-hub[.]com and WebDAV staging |
| Trojan:Script/RedFlick | Defender Signature | Microsoft Defender detection family for RedFlick LNK/scripting stage |
| Backdoor:Python/CosmicPulse | Defender Signature | Microsoft Defender detection for primary post-exploitation Python implant |
File System & Task Telemetry
| Telemetry Artifact | Category | Operational Function |
|---|---|---|
| Internet Quality Test Connection | Windows Scheduled Task | Gathers host telemetry and beacons to C2 infrastructure |
| Network Configuration Manager | Windows Scheduled Task | Mounts WebDAV share pointing to remote attacker server |
| System Health Monitor | Windows Scheduled Task | Invokes control.exe to execute staged CPL downloader |
.LNK (Disguised as .PDF) | Dropper File | Shortcut triggering silent MSI download via SSH or Base64 script |
NOROBOT / BAITSWITCH | Malware Stager | Downloader applet performing anti-VM checks and deploying CosmicPulse |
| DarkSword | Exploit Kit | Chained iOS zero-day toolkit targeting mobile device respondents |
secure-dns-hub.com103.160.59.97Internet Quality Test ConnectionNetwork Configuration ManagerSystem Health MonitorCosmicPulseRedFlickNOROBOTBAITSWITCHDarkSwordStar Blizzard (FSB Center 18)
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light
“Because nation-state APTs strictly observe your weekend plans.”
Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.
// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Japan's Keio Hit by Ransomware; Railway Resilient via Air-Gap
A ransomware attack crippled Keio Corporation's hotel reservations and retail payment systems, while strict OT air-gaps kept Tokyo's trains running on time.

Bitget $387.5M Crypto Heist Exploited Third-Party Security Flaw
Bitget lost $387.5M in a crypto heist after attackers exploited a third-party security flaw to forge withdrawal commands. North Korean Lazarus TTPs confirmed.

Storm-3168 Abuses Leaked Azure SPNs to Delete Cloud Resources
Storm-3168 abused leaked Azure service principals to execute 150+ destructive calls across cloud storage. Only immutable resource locks prevented total wiping.