As reported by BleepingComputer, Microsoft has uncovered a new malware delivery technique dubbed "RedFlick" used by the Russian state-sponsored actor Star Blizzard to deploy its CosmicPulse backdoor. While the individual components — phishing, VHDX containers, LNK execution, scheduled tasks, and WebDAV — are not novel in isolation, the composition and modularity of this chain warrant close attention from defenders.

Threat Intelligence: As reported by BleepingComputer, Microsoft has uncovered a new malware delivery technique dubbed "RedFlick" used by the Russian state-sponsored actor Star Blizzard to deploy its CosmicPulse backdoor.

Why RedFlick Matters Beyond the Headline

The significance of RedFlick isn't a single breakthrough technique — it's the operational engineering behind it. Star Blizzard has deliberately decomposed the infection chain into discrete scheduled-task roles, each handling a narrow function: reconnaissance (Internet Quality Test Connection), infrastructure preparation (Network Configuration Manager), and payload retrieval (System Health Monitor). This modular design creates natural failover and detection-evasion points. If one task is caught by EDR, the others may persist or be re-seeded independently.

This is a meaningful evolution from the actor's earlier spear-phishing operations. By reducing the infection to a single user action — opening a disguised LNK inside a VHDX — Star Blizzard has lowered the friction required for successful compromise while increasing the complexity burden on defenders who must now correlate activity across multiple seemingly-legitimate maintenance tasks.

The VHDX and WebDAV Combination Deserves Scrutiny

The use of a Virtual Hard Disk (VHDX) as a transport container is notable. VHDX files bypass many traditional sandboxing and file-type filters that focus on executable formats. Mounted as a virtual disk, the LNK inside executes in a context that some monitoring solutions under-instrument. Pairing this with WebDAV for lateral payload retrieval further complicates network-based detection, since traffic may resemble legitimate file-share activity over standard ports.

Key takeaway: RedFlick's strength is composability, not novelty. Each stage looks mundane in isolation — that's the design goal.

Who Is at Greatest Risk

Who Is at Greatest Risk
Government and defense-sector organizations in NATO and allied nations — Star Blizzard's historical targeting priorities.
Think tanks, policy NGOs, and academic institutions engaged in geopolitical research — frequent secondary targets for credential and document theft.
Organizations with weak email filtering that permit password-protected archives through perimeter controls without detonation or analysis.
Environments without scheduled-task monitoring — the entire chain depends on persistence via schtasks; organizations not baselining and alerting on new task creation are effectively blind to the second stage onward.

Shield53 Recommendations

Immediate Actions

  • Block or detonate password-protected archives at the email gateway. RedFlick's initial delivery depends on ZIP/RAR evasion; quarantine all encrypted archives and require sandboxed inspection before release.
  • Enable and tune scheduled-task monitoring. Alert on new task creation with names mimicking system maintenance utilities (e.g., "Internet Quality Test Connection," "Network Configuration Manager," "System Health Monitor"). Baseline legitimate task names to reduce noise.
  • Restrict VHDX/VHD mounting on endpoints. Where business need doesn't exist, disable AutoMount and block execution of LNK files from virtual disk containers via application control (WDAC, AppLocker).
  • Monitor for WebDAV initiation from unusual processes. The "Network Configuration Manager" task prepares WebDAV; detecting mklink or net use activity targeting WebDAV paths from non-standard processes is a high-signal indicator.
  • Deploy detection for Python-based loaders. CosmicPulse uses a Python 3.8 bootstrapper reading AES-ECB keys from the registry. Alert on Python execution from non-standard paths and on registry writes under HKCU\Software\* containing high-entropy values.

Strategic Posture

Defenders should treat RedFlick as a signal that state actors are investing in delivery infrastructure, not just payload development. The arms race is increasingly about the first 60 seconds of execution — the gap between user action and backdoor deployment. Reducing that detection window through telemetry-rich endpoint tools and aggressive email-layer controls is the most effective counter. Organizations relying on signature-based AV alone will miss this chain entirely until the exfiltration stage.

Additionally, the AES-ECB key embedded in the bootstrapper is a recoverable artifact — once extracted, it can be used to decrypt any CosmicPulse sample variant using the same scheme. Threat intelligence teams should prioritize extracting and sharing this key across ISAC communities to accelerate community-wide detection.