Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Russian State-Linked Hackers Deploy New Automated RedFlick Attack Chain

The cyber-crime group known as Star Blizzard, linked to the Russian state, has begun using a novel RedFlick technique that automates infections via a CosmicPulse backdoor.

The Russian-state-affiliated hacker collective Star Blizzard has shifted to a new RedFlick methodology, embedding the well-known CosmicPulse backdoor into its payloads. The attack begins with a phishing message that appears as a legitimate invitation, followed by a second email with a password-protected ZIP or RAR attachment. Inside, victims find a VHDX virtual disk; opening it and clicking a PDF-masquerading LNK file triggers a hidden window that runs commands while still displaying a PDF view.

In the background, an MSI package is downloaded and installed, launching three seemingly benign maintenance tasks that together hand the attacker complete control of the computer. According to Microsoft, this automated chain eliminates the need for further victim interaction, making the infection rapid and stealthy. The group, operating since 2017, continues to seek fresh techniques for spreading malicious code.

Why it matters

The new automated method makes ransomware and espionage attacks faster and harder to detect for users and organizations.

In this story

RedFlickphishing emailVHDX virtual diskPDF LNK fileMSI installerscheduled tasksautomated infectioncyber-espionage
Get the beta ↗