Organizations affected by RedFlick activity: 100+ (Source: Microsoft Security (September 29, 2026))
Fewer steps give a victim fewer chances to stop
Microsoft describes a change in Star Blizzard, a Russian state-backed group. It says the change reduces friction and likely raises the chance of compromise. The rest of this paragraph is interpretation. Each step asked of a victim is a moment to stop and think. Fewer steps leave fewer of those moments.
Star Blizzard's older attacks leaned on ClickFix lures. Those needed a victim to carry out a series of steps before the backdoor arrived. Microsoft says the new method, RedFlick, needs "a single user interaction." Microsoft has tracked Star Blizzard's changes since January 2026, with the RedFlick scheduled tasks appearing in April.
Microsoft does not say which step that interaction is. The report's own description shows a victim doing several things. They reply to a phishing email. They open the contents of a password-protected archive. In the January version, they open a shortcut disguised as a PDF. The phrase should be read as Microsoft's summary, not as a count of every click.
The targets are Ukrainian individuals and institutions. They also include NGOs, Western think tanks, governments and financial institutions that support Ukraine. Microsoft says the activity has affected over 100 organizations, mainly in the United States and United Kingdom.
How RedFlick works
The chain starts when a target answers the first phishing email. Star Blizzard then sends a follow-up with a password-protected archive. The password appears as an image in the email, not as text.
In January, the archive held a virtual hard disk file. Inside was a shortcut disguised as a PDF. Opening it ran a script. The script opened a decoy PDF and downloaded an installer from a remote server.
By April, the installer created three Windows scheduled tasks. Each was named to look like a routine network component. They were Internet Quality Test Connection, Network Configuration Manager and System Health Monitor.
The tasks split the work. The first sent the computer name and username to the attacker's server. It could also run a remote file. Microsoft could not obtain a sample of that file.
The second task prepared Windows to use WebDAV. WebDAV lets a computer treat a web address like a network folder. The third task ran the next stage, a downloader for CosmicPulse, the group's Python backdoor.
In July, the group changed the chain again. A script searched a downloaded PDF for a marker. It pulled out 208 bytes of encoded text and ran it. Microsoft says these changes point to efforts to streamline deployment and reduce user interaction.
Trust borrowed from other people's websites
The second change is about who sends the email. Before, the group used free Protonmail and Microsoft consumer accounts. Since March, its large-scale campaigns have used accounts on websites running cPanel and WordPress.
Microsoft assesses with high confidence that Star Blizzard compromised those websites. The same account name appeared across many domains. Microsoft does not say how the sites were compromised.
The lures changed too. Some invited people to conferences from a reputable think tank or NGO. Others looked like internal messages from the target's own organization. Campaigns ran from tens to hundreds of emails. Microsoft says this likely reflects a mass-mailing platform.
This shows where a common check breaks down. Defenders often judge a sender by its domain and history. That check is weaker when the domain belongs to an unrelated site that an attacker has taken over.
What the report does not settle
Microsoft could not get a copy of the file the first task runs remotely. Its full effect is unknown. Microsoft also says CosmicPulse received small changes to avoid detection signatures. Its capabilities stayed the same.
The report includes indicators of compromise, detections and hunting guidance for defenders.
Questions for your security team
First, can we alert when an installer creates scheduled tasks with generic network or health names? Second, do staff need to open virtual disk files from email? If not, can we block them?
Third, how do we handle password-protected archives from outside the company? Fourth, does anyone rely on WebDAV, or can we restrict it?
Fifth, if your organization runs cPanel or WordPress sites, who reviews the accounts on them? A site that sends nothing today could become someone else's sender.
The lesson here is that Microsoft describes an actor reducing friction, so defenders should look for the traces the chain leaves behind. A task called System Health Monitor is only routine if you know who installed it.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Microsoft Security.





