Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Russian State Hackers Use New RedFlick Technique to Deploy CosmicPulse Backdoor

Russian State Hackers Use New RedFlick Technique to Deploy CosmicPulse Backdoor

By: Morgan Cipher — Senior Privacy Journalist

Last updated: October 2, 2026

Human Written
Russian State Hackers Use New RedFlick Technique to Deploy CosmicPulse Backdoor
  • Russian state-linked hackers known as Star Blizzard have started using a new attack method called RedFlick to deliver a dangerous backdoor program called CosmicPulse.

  • The attacks start with a phishing email and can infect a computer with just one click from the victim.

  • Over 100 organizations in the United States and United Kingdom have already been affected in 2026.

A Russian hacking group backed by the state has found a new way to break into computers. The group goes by the name Star Blizzard. Microsoft Threat Intelligence caught them using a fresh attack method called RedFlick. The goal is to sneak a backdoor program called CosmicPulse onto victims’ computers without being noticed.

Microsoft has been tracking this group’s activity throughout 2026. What makes RedFlick stand out is how little the victim needs to do. Older attack methods needed victims to click several times. RedFlick can get the job done in just one step. That makes it faster and harder to stop.

How Star Blizzard Gets In

The attack almost always starts with an email. But Star Blizzard does not always go straight in for the kill. Sometimes, the hackers send a friendly first message to the target. They build a little trust. Then they send a follow-up email with a dangerous file attached.

That file is usually a password-protected ZIP or RAR archive. Inside the archive is a virtual hard disk file. That file hides a shortcut designed to look like a normal PDF document. When the victim opens it, hidden commands run in the background. A fake document pops up on screen to stop the victim from getting suspicious.

Early versions of the attack used scripts and an installer file to move to the next stage. By April 2026, Star Blizzard had switched things up again. Microsoft found that the group was now creating three scheduled tasks on infected computers. The tasks were named to look like normal Windows system tools. They used names like “Internet Quality Test Connection,” “Network Configuration Manager,” and “System Health Monitor.”

These tasks are not what they look like. They quietly connect the infected computer to servers controlled by the attackers. They also help run more harmful programs in the background.

After those tasks are in place, a downloader program comes in. Microsoft calls it NOROBOT or BAITSWITCH. That downloader’s one job is to install CosmicPulse. CosmicPulse is a Python-based backdoor. It gives the attackers a permanent way back into the computer whenever they want. According to Microsoft, CosmicPulse is not cryptojacking malware. Its only documented role in these attacks is maintaining access to compromised systems.

Who They Are Going After

Star Blizzard did not pick random targets. The group has been going after specific types of people and organizations. Microsoft says the targets include Ukrainian individuals and institutions. International non-governmental organizations are also on the list. So are think tanks, governments, and financial institutions connected to support for Ukraine.

Most of the affected organizations are based in the United States and the United Kingdom. In total, Microsoft has observed more than 100 organizations caught in these attacks so far.

SecurityWeek reports that Microsoft tracked more than a dozen RedFlick campaigns between January and August 2026 alone. The group has also grown bolder. Russian hackers have also faced direct attention from U.S. authorities, with a $10 million reward offered for information on hackers targeting Signal.

Earlier attacks were narrowly targeted at specific people. Now, the campaigns are bigger. The hackers have reportedly used already-compromised websites to send out phishing messages at a larger scale.

The Attack Keeps Changing Shape

One thing that makes Star Blizzard hard to stop is that they keep adjusting their methods. They have used VHDX files, scheduled tasks, PowerShell commands, and installer files across different campaigns. Swapping out these tools regularly makes it harder for security software to catch them.

Microsoft notes that RedFlick cuts down the infection process to just one user action. That is a step down from previous methods that required multiple clicks from the victim. Fewer steps mean fewer chances for someone to notice something is wrong and back out.

BleepingComputer confirms that this represents a clear shift in how the group works. Instead of sticking with one playbook, Star Blizzard keeps refining its approach. That pattern shows the group is not slowing down. If anything, it is getting more efficient.

Share this article

You might also like

Russian-Speaking Forum Buyer Seeks Unique WordPress Admin Credentials

Dark Web Buyer Seeks WordPress Admin Access to High-Traffic Websites

A forum actor is seeking valid WordPress administrator access, with unique credentials and higher-traffic sites reportedly attracting more interest. The…

October 2, 2026
Hacker Claims Over 300,000 Mexican Tuberculosis Records are for Sale

Hacker Claims Mexico’s Tuberculosis Database is for Sale with 305,000 Patient Records

Someone on a cybercrime forum claims to hold 305,852 tuberculosis records from Mexico’s national disease tracking system, and is selling…

September 30, 2026
Polish Healthcare Software Firm Qbusoft Confirms Patient Data Breach

Qbusoft Cyberattack Exposes Sensitive Patient Data as Polish Regulators Investigate

Hackers broke into Qbusoft, a Polish company that builds software for hospitals and clinics, and stole patient data. The stolen…

September 30, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.