MICROSOFT Threat Intelligence has detailed Star Blizzard’s 2026 evolution of phishing and malware delivery, focusing on a RedFlick technique that accelerates and broadens compromise through user-friendly infection flows.
Since January 2026, the group has moved from targeted spear phishing to large-scale initial contact campaigns, leveraging compromised websites to create sender infrastructure and adopting RedFlick to trigger a new, scheduler-based malware delivery that can install the CosmicPulse backdoor with a single user interaction.
The shift is accompanied by a rise in phishing volume, broader targeting of Ukrainian-oriented assets, NGOs, think tanks, governments and related organisations, and evidence of activity affecting over 100 organisations in the US and UK.
RedFlick hinges on a sequence of techniques designed to evade detection and scale operations. Early 2026 campaigns used password-protected ZIPs and VHDX lures, with LNK files disguised as PDFs that spawn hidden commands to download a CosmicPulse downloader.
In April 2026, Star Blizzard expanded persistence to three scheduled tasks masquerading as legitimate components (Internet Quality Test Connection, Network Configuration Manager, System Health Monitor) to exfiltrate host data and to fetch and execute the CosmicPulse backdoor via a remote CPL applet. July 2026 introduced a multistage chain: PDFs conceal payloads; a PowerShell stage decodes data embedded in PDFs and downloads further MSI components, which again create additional tasks.
The downloader operates under the moniker NOROBOT/BAITSWITCH, delivering CosmicPulse, and using registry keys and AES-based decoding to persist. Defences emphasise enhanced phishing resistance, EDR in block mode, Safe Links/Attachments, cloud protection, and Defender for Office 365 controls, alongside hunting queries for conhost[.]exe with curl, SSH-based deployments, and scheduled-task persistence.