Organizations affected by RedFlick activity: 100+ (Source: Microsoft Threat Intelligence (September 29, 2026))
Microsoft's new report on the Russian group Star Blizzard describes a trade. The attacker asks less of the victim and more of the defender's tools. Each step removed for the target is another step a security team must learn to spot.
What Microsoft found
Since January 2026, Microsoft has watched Star Blizzard change its tactics. The company has reported on the group since 2023. Its latest findings say the group has moved beyond purely targeted spear-phishing, where an attacker writes to a chosen person. It now also runs large campaigns, with tens to hundreds of emails each.
Microsoft says this likely reflects a mass-mailing phishing platform. The earliest campaigns, in January and February, posed as Ukrainian authorities and sent tax-audit and fine notices to users of the Ukr.net email service. Since March, the lures have mostly been invitations to closed-door events, such as a roundtable on European security, supposedly hosted by a known think tank or NGO. Some emails are made to look like internal messages from the target's own organization.
Most are in the United States and United Kingdom. Microsoft says it is notifying targeted customers directly. The Hacker News noted that the number of organizations actually breached has not been disclosed. "Affected" is not the same as "compromised."
The U.S. cyber agency CISA attributes Star Blizzard to Centre 18 of Russia's Federal Security Service (FSB). Microsoft says the organizations most at risk are government, NGO and think-tank bodies tied to Ukraine policy. Its campaign timeline also lists lures aimed at technology-sector organizations in the US and Europe, and at international financial organizations.
How the infection works
The first email usually carries no attachment. If the recipient replies, Star Blizzard typically sends a password-protected archive. The password appears as an image in the email.
Inside is a shortcut file disguised as a PDF. Opening it runs commands in a hidden window and fetches a Windows installer from a remote server. Microsoft calls this technique RedFlick, and says it needs a single user interaction. In the chain described here, that interaction is opening the shortcut file. It comes after the target has replied and unpacked the archive. The group's earlier ClickFix method made victims complete several actions first.
The installer then creates scheduled tasks, which are jobs Windows runs on its own. By April, there were three, all named to look like ordinary network components. Each has a separate role.
The first task reports the computer and user name back to the attacker's server. It can also pull in and run more code from a remote address. The second task readies Windows for WebDAV, so that a web address can be treated like a shared folder. The other tasks depend on this. The third task, named System Health Monitor, calls control.exe to reach the attacker's server and start the next stage.
That next stage is a small program built to pass as a Control Panel add-on. Its only job is to download and set up CosmicPulse, a backdoor written in Python. Microsoft says the backdoor's purpose has not changed, though small edits keep it ahead of detection signatures.
One limit is worth stating. Microsoft could not obtain the payload the first task can run remotely, so what it does is unknown.
Your website can be the sender
Since March, Star Blizzard has sent many of these emails from accounts created on websites running cPanel and WordPress. Microsoft assesses with high confidence that the group compromised those sites for this purpose. It used the same account name across several domains.
Before, the group mostly used free mail accounts such as Proton and Microsoft consumer services. Presumably a hacked website lends its own standing to the message, and its owner may not know it is being used. That is our interpretation. The sources do not say it.
What this means for leaders
This shows a pattern in how the attack is built. The human step is made as small as possible. The technical chain behind it is made longer. A training program alone addresses only the first half.
Microsoft itself calls the chain increasingly complex and aimed at layered defenses. That is why detection has to look at behavior, such as a hidden window launching curl or a task with a plausible name.
Questions to put to your security team:
First, can we detect conhost.exe launching curl, or SSH starting a local command? Microsoft publishes hunting queries for both, and warns they can flag harmless activity too. Second, who reviews scheduled tasks on staff laptops, and would a task named "System Health Monitor" stand out? Third, have our own websites been checked for unknown user accounts? Fourth, do staff know that an invitation from a colleague's address can still be a lure?
Microsoft's stated focus is Ukraine-linked policy bodies. Its timeline also shows lures sent to technology and financial organizations. Whatever your sector, these questions test how well your defenses handle an attack that asks very little of the person it targets.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Microsoft.





