CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2threat

Star Blizzard's RedFlick: mass-mailed think-tank event invitations, compromised-website senders and a single-click scheduled-task chain to the CosmicPulse backdoor

Microsoft: Star Blizzard adds mass mailings and a one-click scheduled-task chain to its CosmicPulse backdoor delivery

Analysis

Microsoft Threat Intelligence reports that Star Blizzard, which CISA attributes to Russia's FSB Centre 18 (Microsoft Threat Intelligence, 2026-09-29) and which CyberScoop lists under the names SEABORGIUM, Callisto Group, TA446 and COLDRIVER (CyberScoop, 2026-09-29), has since January 2026 added large-scale phishing to its targeted spear-phishing: at least 13 distinct campaigns of tens to hundreds of emails each, aimed primarily at NGOs, think tanks and government organizations, with Ukrainian individuals and institutions, diplomatic and multilateral bodies and financial organizations also named (Microsoft Threat Intelligence, 2026-09-29). Microsoft counts over 100 affected organizations, primarily in the United States and United Kingdom, and infers the actor now uses a mass-mailing platform (Microsoft Threat Intelligence, 2026-09-29). The lures are invitations to closed-door roundtables that borrow the names of real think tanks, often written to look like internal mail from the target's own organization; the first message is usually without an attachment, and a reply is answered with a password-protected RAR or ZIP archive whose password is shown as an image, although the Ukraine-focused campaigns and a few later ones attached the lure directly (Microsoft Threat Intelligence, 2026-09-29). Since March the sending accounts sit on WordPress and cPanel websites, replacing free Proton and Microsoft consumer mailboxes, and Microsoft assesses with high confidence that Star Blizzard compromised those sites (Microsoft Threat Intelligence, 2026-09-29). One March campaign instead gave respondents a link to the DarkSword iOS backdoor installation, which Microsoft says Proofpoint reported, and a mid-August campaign employed steganography to conceal identifiers (Microsoft Threat Intelligence, 2026-09-29).

The delivery chain changed three times in 2026 and replaced the ClickFix flow of earlier campaigns with one that needs a single user interaction (Microsoft Threat Intelligence, 2026-09-29). From mid-January, a virtual hard disk file in the archive held a shortcut disguised as a PDF that started a hidden console window and a batch script; the script opened a decoy PDF and ran the SSH client with PermitLocalCommand enabled to download and run a remote MSI, which created a scheduled task that used control.exe to fetch the CosmicPulse downloader disguised as a Control Panel applet (Microsoft Threat Intelligence, 2026-09-29). From April the MSI created three scheduled tasks named like network components: one beaconing host and user names to the command server and running a remote DLL through a WebDAV path, one preparing WebDAV support, and one running control.exe against a remote path to execute the next stage (Microsoft Threat Intelligence, 2026-09-29). From July, a shortcut used conhost.exe and curl to download a PDF, and PowerShell then searched that file for a marker, decoded the Base64 blob that follows it and ran the result to fetch another MSI (Microsoft Threat Intelligence, 2026-09-29). The downloader fetches two ZIP archives, stores an encrypted AES key in a registry key under HKCU\Software\Classes, and a Python bootstrapper decrypts and runs the CosmicPulse payload, which is publicly tracked as YESROBOT (Microsoft Threat Intelligence, 2026-09-29).

Where each step surfaces: mail-flow logs show bulk initial-contact invitations and a follow-up with a password-protected archive; process-creation telemetry with parent lineage shows a hidden console window spawning a command shell that runs an SSH client, msiexec started from a script, control.exe loading a remote path, and conhost.exe with curl downloading a PDF that PowerShell then parses; scheduled-task creation events show tasks named like network components, one pointing at a WebDAV path; registry telemetry shows a key written under HKCU\Software\Classes. Microsoft's recommended controls include phishing-resistant authentication, Conditional Access, Safe Links and Safe Attachments with zero-hour auto purge, EDR in block mode, and Windows Firewall rules restricting outbound SSH connection attempts to what the business needs (Microsoft Threat Intelligence, 2026-09-29).

Triage: Microsoft's discriminators for this actor are a sender whose organization name appears only in the local part of the address on an unrelated domain, bulk delivery, an initial message that is usually without an attachment and a follow-up archive after a reply (Microsoft Threat Intelligence, 2026-09-29).

Cited evidence

Since January 2026, Microsoft observed at least 13 distinct large-scale phishing campaigns targeting primarily NGOs, think tanks, and government organizations worldwide.

By contrast, the RedFlick infection flow only requires a single user interaction, reducing friction in the compromise process.

Microsoft Threat Intelligence assesses with high confidence that these websites have been compromised by Star Blizzard for this purpose.

The emails in these RedFlick campaigns are often sent in bulk.

Microsoft Threat Intelligence 2026-09-29

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.