// 2 ZERO-DAY · 5 CVE · 5 EXPLOIT IN THE LAST 24H→
Star Blizzard has replaced ClickFix with RedFlick, an infection chain requiring a single click. Since January, 13 mass campaigns have hit over 100 organizations.

Star Blizzard, the FSB Center 18 APT active since 2017, adopted RedFlick as its new infection chain starting in January 2026. The technique requires a single user interaction, compared to the multiple actions needed with the previous ClickFix, expanding the actor's reach from targeted operations to mass campaigns that have hit over 100 organizations in the United States and United Kingdom.

Key Takeaways
  • RedFlick shortens the infection chain to a single click, eliminating the friction that limited previous ClickFix campaigns.
  • Since January 2026, Microsoft has detected 13 large-scale phishing campaigns, with global expansion beginning in March.
  • Over 100 organizations have been hit, primarily think tanks, NGOs, governments, and financial institutions.
  • The July 2026 variant hides PowerShell payloads inside seemingly legitimate PDFs, raising the level of camouflage.

How RedFlick Works: The Single-Click Chain

The RedFlick chain starts from password-protected ZIP, RAR, or VHDX archives containing LNK files disguised as PDFs. Once triggered, the file leverages conhost.exe and cmd.exe to execute an MSI installer, which installs scheduled tasks for persistence. From there, the system downloads intermediate downloaders identified as NoroBot or BaitSwitch, culminating in the CosmicPulse backdoor written in Python.

According to Microsoft documentation, scheduled tasks observed in April 2026 carried specific names: "Internet Quality Test Connection," "Network Configuration Manager," and "System Health Monitor." The choice of names resembling system utilities reduces visibility for security operators analyzing scheduling logs.

In July 2026, a variant emerged that hides PowerShell payloads inside seemingly legitimate PDFs. Once opened, the PDF creates scheduled tasks and launches the CPL-based downloader that leads to CosmicPulse. The use of everyday formats like PDFs to transport executable code signals an evolution toward greater camouflage compared to previous VHDX chains.

"As part of this evolution, Star Blizzard adopted RedFlick, a malware delivery technique that helps evade detection by initiating a set of scheduled tasks to deploy the actor's custom backdoor, CosmicPulse."
— Microsoft Threat Intelligence (via Dark Reading)

From ClickFix to RedFlick: The Attack Economics Shift

ClickFix required the victim to perform multiple successive actions: the initial interaction, copying code from a fake dialog, and manual execution. RedFlick eliminates these steps. The reduced friction transforms the cost per potential victim, allowing the actor to move from dozens of selected targets to hundreds of recipients per campaign.

The quantitative expansion is documented in the timeline: the first campaigns in January–February 2026 targeted exclusively Ukr.net users with messages impersonating the Ukrainian tax authority. From March, the scope widened globally. Accounts created on compromised sites enable sending dozens or hundreds of emails per campaign, likely via a mass-mailing platform.

The source does not specify whether the industrial-scale expansion reduced the per-target success rate, nor how many recipients actually open the attachments. The missing data does not weaken the relevance of the shift: scalability is intrinsic to RedFlick's structure, regardless of immediate yield.

Who Gets Hit and How Victims Are Selected

Over 100 organizations have been hit since March 2026, according to the Microsoft report cited by The Record. The geographic distribution favors the United States and United Kingdom; targeted sectors include think tanks, NGOs, governments, and financial institutions. The political orientation of victims — support for Ukraine — remains consistent with Star Blizzard's historical profile.

Selection no longer occurs through deep research on individuals. Emails are often crafted as internal communications of the target organization, with multiple recipients in the same structure. This approach increases the probability that at least one recipient triggers the chain, compensating with volume what it loses in personalization.

The dossier does not document whether ClickFix victims were migrated progressively or whether the two techniques were employed in parallel before the exclusive adoption of RedFlick. Uncertainty also surrounds the technique's authorship: it is unclear whether RedFlick was developed internally or acquired from other actors.

What to Do Now

Defenses against RedFlick must focus on the friction points the chain does not eliminate. First: opening the password-protected archive, which still requires a user step. Organizations can block incoming ZIP, RAR, and VHDX attachments from external senders, or redirect them to analysis sandboxes before delivery.

Second: scheduled tasks created with system-like names. Security teams should implement detection rules that flag the creation of tasks with generic labels like "Internet Quality Test Connection" or "System Health Monitor," especially when associated with cmd.exe or conhost.exe processes.

Third: PDFs with hidden PowerShell payloads. Security infrastructure must analyze inbound PDF documents with engines that extract embedded scripts, not just Office macros. The July 2026 variant demonstrates that the PDF format is not neutral.

Fourth: the use of compromised sites for mass sending. Filtering must consider not only SMTP sender reputation but also sending patterns: dozens or hundreds of emails with similar subjects from recently created accounts on heterogeneous domains.

Why This Matters

The structural novelty of RedFlick lies in the combination of three elements: reduction to a single user interaction, use of trusted Windows components to camouflage execution, and payload concealment in everyday formats like PDF. The absence of suspicious user requests — copy-pasting code, manual execution — eliminates the behavioral signals that traditionally trigger alerts.

Star Blizzard's ability to evolve from patient operations to industrial-scale campaigns while retaining the custom CosmicPulse backdoor indicates the group has recalibrated the ratio between sophistication and scalability. The trend is observable: other APTs with access to mass-mailing platforms could replicate the model, even without replicating the same technical chain.

Frequently Asked Questions

What changed compared to previous Star Blizzard campaigns?

The transition from ClickFix to RedFlick shortened the compromise chain from multiple interactions to a single one, and extended the reach from targeted spear-phishing to mass campaigns with hundreds of emails. The final backdoor, CosmicPulse, remains Python-based.

Are PDF files dangerous even without executable attachments?

The July 2026 variant hides PowerShell payloads inside the PDF itself. The format is not neutral: opening the document launches the infection chain without further user confirmation.

Why do scheduled tasks use system-like names?

The use of labels like "System Health Monitor" or "Network Configuration Manager" fits a camouflage pattern: the malware mimics legitimate labels to blend into ordinary scheduling logs, reducing the likelihood of manual inspection.

Information is based on cited sources and current as of publication.

Sources


Sources and references
  1. darkreading.com
  2. securityweek.com
  3. therecord.media
  4. podcast.securityweek.com