CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Star Blizzard RedFlick campaigns (2026)

campaign · campaign:star-blizzard-redflick-2026 single-source

At least 13 large-scale Star Blizzard phishing campaigns since January 2026 using the RedFlick single-interaction scheduled-task chain to install CosmicPulse; Microsoft counts over 100 affected organizations, primarily in the US and UK (Microsoft, 2026-09-29).

Aliases: RedFlick

Coverage
1
first 2026-09-30 → last 2026-09-30
Latest activity
2026-09-30
Microsoft: Star Blizzard adds mass mailings and a one-click scheduled-task chain to its CosmicPulse backdoor…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance · regions: us, uk
Sources cited
2
2 hosts

Defender insights

What each entry about Star Blizzard RedFlick campaigns (2026) tells a defender to do, newest first.

2026-09-30NOTABLEMicrosoft: Star Blizzard adds mass mailings and a one-click scheduled-task chain to its CosmicPulse backdoor delivery

Triage

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed to

uses

Story timeline

  1. 2026-09-30Star Blizzard's RedFlick: mass-mailed think-tank event invitations, compromised-website senders and a single-click scheduled-task chain to the CosmicPulse backdoor
    active-threatsMicrosoft: Star Blizzard adds mass mailings and a one-click scheduled-task chain to its CosmicPulse backdoor delivery
ATT&CK techniques (16 across 8 tactics)

16 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Resource DevelopmentCompromise Infrastructure: Server
  • Initial AccessPhishing · Phishing: Spearphishing Attachment
  • ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell · Command and Scripting Interpreter: Python · User Execution: Malicious File
  • PersistenceScheduled Task/Job: Scheduled Task · Modify Registry
  • Privilege EscalationScheduled Task/Job: Scheduled Task
  • StealthObfuscated Files or Information: Steganography · Masquerading: Masquerade Task or Service · Masquerading: Masquerade File Type · Deobfuscate/Decode Files or Information · Indirect Command Execution · System Binary Proxy Execution: Control Panel
  • Defense ImpairmentModify Registry
  • Command and ControlIngress Tool Transfer

Resource Development TA0042

T1584.004Compromise Infrastructure: Server×1

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×1

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1059.003Command and Scripting Interpreter: Windows Command Shell×1

Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Stealth TA0005

T1027.003Obfuscated Files or Information: Steganography×1

Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1036.004Masquerading: Masquerade Task or Service×1

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1036.008Masquerading: Masquerade File Type×1

Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file’s signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file’s type. For example, the header of a JPEG file, is <code> 0xFF 0xD8</code> and the file extension is either `.JPE`, `.JPEG` or `.JPG`.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1202Indirect Command Execution×1

Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

T1218.002System Binary Proxy Execution: Control Panel×1

Adversaries may abuse control.exe to proxy execution of malicious payloads. The Windows Control Panel process binary (control.exe) handles execution of Control Panel items, which are utilities that allow users to view and adjust computer settings.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Defense Impairment TA0112

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗

Entries about Star Blizzard RedFlick campaigns (2026) (1)

2026-09-30 · view entry permalink →

NOTABLENATOB2

Star Blizzard's RedFlick: mass-mailed think-tank event invitations, compromised-website senders and a single-click scheduled-task chain to the CosmicPulse backdoor

Microsoft Threat Intelligence reports that Star Blizzard, which CISA attributes to Russia's FSB Centre 18 (Microsoft Threat Intelligence, 2026-09-29) and which CyberScoop lists under the names SEABORGIUM, Callisto Group, TA446 and COLDRIVER (CyberScoop, 2026-09-29), has since January 2026 added large-scale phishing to its targeted spear-phishing: at least 13 distinct campaigns of tens to hundreds of emails each, aimed primarily at NGOs, think tanks and government organizations, with Ukrainian individuals and institutions, diplomatic and multilateral bodies and financial organizations also named (Microsoft Threat Intelligence, 2026-09-29). Microsoft counts over 100 affected organizations, primarily in the United States and United Kingdom, and infers the actor now uses a mass-mailing platform (Microsoft Threat Intelligence, 2026-09-29). The lures are invitations to closed-door roundtables that borrow the names of real think tanks, often written to look like internal mail from the target's own organization; the first message is usually without an attachment, and a reply is answered with a password-protected RAR or ZIP archive whose password is shown as an image, although the Ukraine-focused campaigns and a few later ones attached the lure directly (Microsoft Threat Intelligence, 2026-09-29). Since March the sending accounts sit on WordPress and cPanel websites, replacing free Proton and Microsoft consumer mailboxes, and Microsoft assesses with high confidence that Star Blizzard compromised those sites (Microsoft Threat Intelligence, 2026-09-29). One March campaign instead gave respondents a link to the DarkSword iOS backdoor installation, which Microsoft says Proofpoint reported, and a mid-August campaign employed steganography to conceal identifiers (Microsoft Threat Intelligence, 2026-09-29).

The delivery chain changed three times in 2026 and replaced the ClickFix flow of earlier campaigns with one that needs a single user interaction (Microsoft Threat Intelligence, 2026-09-29). From mid-January, a virtual hard disk file in the archive held a shortcut disguised as a PDF that started a hidden console window and a batch script; the script opened a decoy PDF and ran the SSH client with PermitLocalCommand enabled to download and run a remote MSI, which created a scheduled task that used control.exe to fetch the CosmicPulse downloader disguised as a Control Panel applet (Microsoft Threat Intelligence, 2026-09-29). From April the MSI created three scheduled tasks named like network components: one beaconing host and user names to the command server and running a remote DLL through a WebDAV path, one preparing WebDAV support, and one running control.exe against a remote path to execute the next stage (Microsoft Threat Intelligence, 2026-09-29). From July, a shortcut used conhost.exe and curl to download a PDF, and PowerShell then searched that file for a marker, decoded the Base64 blob that follows it and ran the result to fetch another MSI (Microsoft Threat Intelligence, 2026-09-29). The downloader fetches two ZIP archives, stores an encrypted AES key in a registry key under HKCU\Software\Classes, and a Python bootstrapper decrypts and runs the CosmicPulse payload, which is publicly tracked as YESROBOT (Microsoft Threat Intelligence, 2026-09-29).

Where each step surfaces: mail-flow logs show bulk initial-contact invitations and a follow-up with a password-protected archive; process-creation telemetry with parent lineage shows a hidden console window spawning a command shell that runs an SSH client, msiexec started from a script, control.exe loading a remote path, and conhost.exe with curl downloading a PDF that PowerShell then parses; scheduled-task creation events show tasks named like network components, one pointing at a WebDAV path; registry telemetry shows a key written under HKCU\Software\Classes. Microsoft's recommended controls include phishing-resistant authentication, Conditional Access, Safe Links and Safe Attachments with zero-hour auto purge, EDR in block mode, and Windows Firewall rules restricting outbound SSH connection attempts to what the business needs (Microsoft Threat Intelligence, 2026-09-29).

Triage: Microsoft's discriminators for this actor are a sender whose organization name appears only in the local part of the address on an unrelated domain, bulk delivery, an initial message that is usually without an attachment and a follow-up archive after a reply (Microsoft Threat Intelligence, 2026-09-29).

Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide.

By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process.

Microsoft Threat Intelligence assesses with high confidence that these websites have been compromised by Star Blizzard for this purpose.

The emails in these RedFlick campaigns are often sent in bulk.

Microsoft Threat Intelligence 2026-09-29
threat30 Sep 04:42Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • cyberscoop.com1 (50%)
  • microsoft.com1 (50%)