As reported by BleepingComputer, Microsoft has uncovered a new malware delivery technique dubbed "RedFlick" used by the Russian state-sponsored actor Star Blizzard to deploy its CosmicPulse backdoor. While the individual components — phishing, VHDX containers, LNK execution, scheduled tasks, and WebDAV — are not novel in isolation, the composition and modularity of this chain warrant close attention from defenders.
Why RedFlick Matters Beyond the Headline
The significance of RedFlick isn't a single breakthrough technique — it's the operational engineering behind it. Star Blizzard has deliberately decomposed the infection chain into discrete scheduled-task roles, each handling a narrow function: reconnaissance (Internet Quality Test Connection), infrastructure preparation (Network Configuration Manager), and payload retrieval (System Health Monitor). This modular design creates natural failover and detection-evasion points. If one task is caught by EDR, the others may persist or be re-seeded independently.
This is a meaningful evolution from the actor's earlier spear-phishing operations. By reducing the infection to a single user action — opening a disguised LNK inside a VHDX — Star Blizzard has lowered the friction required for successful compromise while increasing the complexity burden on defenders who must now correlate activity across multiple seemingly-legitimate maintenance tasks.
The VHDX and WebDAV Combination Deserves Scrutiny
The use of a Virtual Hard Disk (VHDX) as a transport container is notable. VHDX files bypass many traditional sandboxing and file-type filters that focus on executable formats. Mounted as a virtual disk, the LNK inside executes in a context that some monitoring solutions under-instrument. Pairing this with WebDAV for lateral payload retrieval further complicates network-based detection, since traffic may resemble legitimate file-share activity over standard ports.
Key takeaway: RedFlick's strength is composability, not novelty. Each stage looks mundane in isolation — that's the design goal.
Who Is at Greatest Risk
Shield53 Recommendations
Immediate Actions
- Block or detonate password-protected archives at the email gateway. RedFlick's initial delivery depends on ZIP/RAR evasion; quarantine all encrypted archives and require sandboxed inspection before release.
- Enable and tune scheduled-task monitoring. Alert on new task creation with names mimicking system maintenance utilities (e.g., "Internet Quality Test Connection," "Network Configuration Manager," "System Health Monitor"). Baseline legitimate task names to reduce noise.
- Restrict VHDX/VHD mounting on endpoints. Where business need doesn't exist, disable AutoMount and block execution of LNK files from virtual disk containers via application control (WDAC, AppLocker).
- Monitor for WebDAV initiation from unusual processes. The "Network Configuration Manager" task prepares WebDAV; detecting
mklinkornet useactivity targeting WebDAV paths from non-standard processes is a high-signal indicator. - Deploy detection for Python-based loaders. CosmicPulse uses a Python 3.8 bootstrapper reading AES-ECB keys from the registry. Alert on Python execution from non-standard paths and on registry writes under
HKCU\Software\*containing high-entropy values.
Strategic Posture
Defenders should treat RedFlick as a signal that state actors are investing in delivery infrastructure, not just payload development. The arms race is increasingly about the first 60 seconds of execution — the gap between user action and backdoor deployment. Reducing that detection window through telemetry-rich endpoint tools and aggressive email-layer controls is the most effective counter. Organizations relying on signature-based AV alone will miss this chain entirely until the exfiltration stage.
Additionally, the AES-ECB key embedded in the bootstrapper is a recoverable artifact — once extracted, it can be used to decrypt any CosmicPulse sample variant using the same scheme. Threat intelligence teams should prioritize extracting and sharing this key across ISAC communities to accelerate community-wide detection.