deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Star Blizzard's RedFlick chain uses Windows scheduled tasks to deploy CosmicPulse backdoor

Microsoft Threat Intelligence documents Star Blizzard's RedFlick phishing technique, which chains LNK files, scheduled tasks and a Python-based loader to deploy the CosmicPulse backdoor.

Star Blizzard's RedFlick chain uses Windows scheduled tasks to deploy CosmicPulse backdoor

Microsoft Threat Intelligence has documented a new delivery technique used by the Star Blizzard activity group, according to a summary of the September 29, 2026 report published on dev.to. Dubbed RedFlick, the technique chains phishing emails, malicious shortcut files, and Windows scheduled tasks to install the CosmicPulse backdoor. The report ties it to at least 13 large-scale campaigns affecting more than 100 organizations during 2026, and describes a sequence that needs fewer user interactions than the ClickFix pattern to reach persistence and deploy a backdoor.

From phishing email to backdoor

Star Blizzard, also tracked as SEABORGIUM, opens with emails sent from accounts on compromised websites or free webmail services, posing as meeting invitations, tax notifications, fine notices, or invoices. Targets who reply typically receive a password-protected ZIP or RAR archive containing an LNK shortcut, sometimes disguised as a PDF. Some campaigns attached lures directly to the first email without waiting for a reply.

Microsoft describes the chain as “one-click,” but as the dev.to summary clarifies, that label covers only the sequence that runs after the victim executes the LNK; replying to the email and extracting the archive remain part of the process.

The report outlines three distinct campaign configurations. In January 2026, an LNK disguised as a PDF sat inside a VHDX disk image within a ZIP archive. Execution ran from the LNK through conhost.exe and cmd.exe to a batch file, which abused the PermitLocalCommand feature of ssh.exe to retrieve and execute a remote MSI installer, while a decoy PDF opened to distract the user. The MSI created one scheduled task.

In April 2026, phishing emails delivered an LNK and MSI directly. The MSI registered three scheduled tasks disguised as legitimate network components, one of which acted as an auxiliary for retrieving a remote payload over WebDAV/WebClient. Microsoft observed CosmicPulse deployed by one of the remaining tasks in at least one incident, though the report notes one referenced DLL sample was never obtained.

In July 2026, an LNK inside a password-protected RAR nested in a ZIP used curl to download a PDF, and PowerShell extracted Base64-encoded data from it — the decoding happens in script, not when the PDF is viewed normally — before attempting to download and execute an MSI. A later stage tried to create two additional tasks for retrieving and running a CPL-type downloader.

Whichever path succeeds, downloaders launched by the scheduled tasks pull down the Python runtime and an encrypted CosmicPulse payload. A bootstrapper reads an encrypted AES key from the registry location HKCU\Software\Classes.mollis, recovers it using an embedded key in AES-ECB mode, and decrypts the payload before execution. The resulting Python-based backdoor then establishes persistence and handles command-and-control communication on the Windows endpoint.

Scale and related tracking

Beyond the 13 campaigns and the more than 100 affected organizations, the summary notes that Microsoft does not explicitly state the backdoor executed successfully in all cases. The report references Google Threat Intelligence's tracking of the same tooling under the names COLDCOPY and CosmicPulse, and points to CISA advisory AA23-341A as related coverage. The dev.to summary rates the overall severity as high.

What defenders can watch for

The report lists observable signals at each stage: unnatural bulk email from legitimate domains, sender local-parts reused across multiple compromised domains, VHDX or LNK files inside archives, curl launched from conhost, ssh.exe invoked with the PermitLocalCommand option, installer execution via msiexec, suspicious scheduled task registrations, CPL execution through control.exe, and Python processes running under user profiles. Proxy and DNS logs can additionally reveal retrieval of MSI, CPL, and ZIP files, plus traffic to CosmicPulse-related domains and IPs.

Recommended mitigations include quarantining password-protected archives attached to reply threads at the gateway, enforcing policies that block execution of LNK and VHDX files originating from email, applying application control or EDR rules against the specific living-off-the-land patterns, and enforcing phishing-resistant MFA such as FIDO2 to reduce credential-theft risk from related campaigns escalating to account takeover.

Why it matters

RedFlick shows a phishing-focused group extending into large-scale malware delivery that leans almost entirely on built-in Windows tooling — ssh.exe, curl, PowerShell, msiexec, scheduled tasks, and Python — which complicates detection because each component is individually legitimate. Password-protected archives blunt gateway scanning, and reply-based delivery lends the initial messages credibility. For defenders, the practical takeaway is that blocking shortcut files and disk images arriving by email, and treating scheduled task creation as a high-signal endpoint event, can break the chain before CosmicPulse ever runs.

  • #security
  • #phishing
  • #malware
  • #windows
  • #microsoft

Related posts