Russian State-Linked Hackers Deploy New Automated RedFlick Attack Chain
The cyber-crime group known as Star Blizzard, linked to the Russian state, has begun using a novel RedFlick technique that automates infections via a CosmicPulse backdoor.
The Russian-state-affiliated hacker collective Star Blizzard has shifted to a new RedFlick methodology, embedding the well-known CosmicPulse backdoor into its payloads. The attack begins with a phishing message that appears as a legitimate invitation, followed by a second email with a password-protected ZIP or RAR attachment. Inside, victims find a VHDX virtual disk; opening it and clicking a PDF-masquerading LNK file triggers a hidden window that runs commands while still displaying a PDF view.
In the background, an MSI package is downloaded and installed, launching three seemingly benign maintenance tasks that together hand the attacker complete control of the computer. According to Microsoft, this automated chain eliminates the need for further victim interaction, making the infection rapid and stealthy. The group, operating since 2017, continues to seek fresh techniques for spreading malicious code.
Why it matters
The new automated method makes ransomware and espionage attacks faster and harder to detect for users and organizations.
In this story
