2026-09-30NOTABLEMicrosoft: Star Blizzard adds mass mailings and a one-click scheduled-task chain to its CosmicPulse backdoor delivery
CosmicPulse
malware · malware:cosmicpulse single-source
Python backdoor of Star Blizzard, installed by a Control Panel applet downloader that Microsoft says is publicly known as NOROBOT or BAITSWITCH; the payload is publicly tracked as YESROBOT (Microsoft, 2026-09-29).
Aliases: YESROBOT, NOROBOT, BAITSWITCH
Coverage
1
first 2026-09-30 → last 2026-09-30
Latest activity
2026-09-30
Microsoft: Star Blizzard adds mass mailings and a one-click scheduled-task chain to its CosmicPulse backdoor…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance · regions: us, uk
Sources cited
2
2 hosts
Defender insights
What each entry about CosmicPulse tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
used by
- Star Blizzard RedFlick campaigns (2026)The RedFlick chain installs the CosmicPulse backdoor through a downloader disguised as a Control Panel applet.
Story timeline
ATT&CK techniques (16 across 8 tactics)
16 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentCompromise Infrastructure: Server
- Initial AccessPhishing · Phishing: Spearphishing Attachment
- ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell · Command and Scripting Interpreter: Python · User Execution: Malicious File
- PersistenceScheduled Task/Job: Scheduled Task · Modify Registry
- Privilege EscalationScheduled Task/Job: Scheduled Task
- StealthObfuscated Files or Information: Steganography · Masquerading: Masquerade Task or Service · Masquerading: Masquerade File Type · Deobfuscate/Decode Files or Information · Indirect Command Execution · System Binary Proxy Execution: Control Panel
- Defense ImpairmentModify Registry
- Command and ControlIngress Tool Transfer
Resource Development TA0042
T1584.004Compromise Infrastructure: Server×1
Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Initial Access TA0001
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1566.001Phishing: Spearphishing Attachment×1
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1059.003Command and Scripting Interpreter: Windows Command Shell×1
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Stealth TA0005
T1027.003Obfuscated Files or Information: Steganography×1
Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1036.004Masquerading: Masquerade Task or Service×1
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1036.008Masquerading: Masquerade File Type×1
Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file’s signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file’s type. For example, the header of a JPEG file, is <code> 0xFF 0xD8</code> and the file extension is either `.JPE`, `.JPEG` or `.JPG`.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1202Indirect Command Execution×1
Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
T1218.002System Binary Proxy Execution: Control Panel×1
Adversaries may abuse control.exe to proxy execution of malicious payloads. The Windows Control Panel process binary (control.exe) handles execution of Control Panel items, which are utilities that allow users to view and adjust computer settings.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Defense Impairment TA0112
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-09-30/star-blizzard-redflick-cosmicpulse-single-click-chain · ATT&CK page ↗
Entries about CosmicPulse (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- cyberscoop.com1 (50%)
- microsoft.com1 (50%)