-
Russian state-linked hackers known as Star Blizzard have started using a new attack method called RedFlick to deliver a dangerous backdoor program called CosmicPulse.
-
The attacks start with a phishing email and can infect a computer with just one click from the victim.
-
Over 100 organizations in the United States and United Kingdom have already been affected in 2026.
A Russian hacking group backed by the state has found a new way to break into computers. The group goes by the name Star Blizzard. Microsoft Threat Intelligence caught them using a fresh attack method called RedFlick. The goal is to sneak a backdoor program called CosmicPulse onto victims’ computers without being noticed.
Microsoft has been tracking this group’s activity throughout 2026. What makes RedFlick stand out is how little the victim needs to do. Older attack methods needed victims to click several times. RedFlick can get the job done in just one step. That makes it faster and harder to stop.
How Star Blizzard Gets In
The attack almost always starts with an email. But Star Blizzard does not always go straight in for the kill. Sometimes, the hackers send a friendly first message to the target. They build a little trust. Then they send a follow-up email with a dangerous file attached.
That file is usually a password-protected ZIP or RAR archive. Inside the archive is a virtual hard disk file. That file hides a shortcut designed to look like a normal PDF document. When the victim opens it, hidden commands run in the background. A fake document pops up on screen to stop the victim from getting suspicious.
Early versions of the attack used scripts and an installer file to move to the next stage. By April 2026, Star Blizzard had switched things up again. Microsoft found that the group was now creating three scheduled tasks on infected computers. The tasks were named to look like normal Windows system tools. They used names like “Internet Quality Test Connection,” “Network Configuration Manager,” and “System Health Monitor.”
These tasks are not what they look like. They quietly connect the infected computer to servers controlled by the attackers. They also help run more harmful programs in the background.
After those tasks are in place, a downloader program comes in. Microsoft calls it NOROBOT or BAITSWITCH. That downloader’s one job is to install CosmicPulse. CosmicPulse is a Python-based backdoor. It gives the attackers a permanent way back into the computer whenever they want. According to Microsoft, CosmicPulse is not cryptojacking malware. Its only documented role in these attacks is maintaining access to compromised systems.
Who They Are Going After
Star Blizzard did not pick random targets. The group has been going after specific types of people and organizations. Microsoft says the targets include Ukrainian individuals and institutions. International non-governmental organizations are also on the list. So are think tanks, governments, and financial institutions connected to support for Ukraine.
Most of the affected organizations are based in the United States and the United Kingdom. In total, Microsoft has observed more than 100 organizations caught in these attacks so far.
SecurityWeek reports that Microsoft tracked more than a dozen RedFlick campaigns between January and August 2026 alone. The group has also grown bolder. Russian hackers have also faced direct attention from U.S. authorities, with a $10 million reward offered for information on hackers targeting Signal.
Earlier attacks were narrowly targeted at specific people. Now, the campaigns are bigger. The hackers have reportedly used already-compromised websites to send out phishing messages at a larger scale.
The Attack Keeps Changing Shape
One thing that makes Star Blizzard hard to stop is that they keep adjusting their methods. They have used VHDX files, scheduled tasks, PowerShell commands, and installer files across different campaigns. Swapping out these tools regularly makes it harder for security software to catch them.
Microsoft notes that RedFlick cuts down the infection process to just one user action. That is a step down from previous methods that required multiple clicks from the victim. Fewer steps mean fewer chances for someone to notice something is wrong and back out.
BleepingComputer confirms that this represents a clear shift in how the group works. Instead of sticking with one playbook, Star Blizzard keeps refining its approach. That pattern shows the group is not slowing down. If anything, it is getting more efficient.