Star Blizzard Changed Its Phishing Game — RedFlick Turns One Click Into Malware
- The Mess: Star Blizzard has changed its phishing infrastructure and delivery chain. Its new RedFlick technique uses compromised websites and scheduled tasks to deploy the CosmicPulse backdoor after a single user interaction.
- The Damage: A convincing phishing message can now lead to persistent malware without the victim going through the usual multi-step infection routine.
- The Fix: Block suspicious external content, harden scheduled-task creation, monitor compromised websites and treat unexpected script execution as an incident.
Phishing usually asks the victim to do too much.
Click a link.
Open a document.
Enable something.
Copy a command.
Run a script.
Approve a login.
Star Blizzard is trying to remove those steps.
Microsoft Threat Intelligence says the Russian state-linked actor has evolved its operations during 2026 and introduced a delivery technique called RedFlick.
The goal is simple:
Get the victim to interact once.
Then let the infrastructure do the rest.
The old infection chain was already effective
Star Blizzard, also known as SEABORGIUM, has spent years using phishing to target organizations and individuals.
Its campaigns have historically relied heavily on convincing messages, malicious links, compromised infrastructure and credential theft.
Earlier in 2026, Microsoft observed the actor using ClickFix-style infection chains.
Those attacks require the victim to perform several actions.
The user sees instructions.
The user copies something.
The user executes it.
The attacker gets code execution.
RedFlick changes the economics.
The victim doesn’t need to complete the entire attack chain manually.
RedFlick moves the work to the attacker
Microsoft says RedFlick is a malware-delivery technique used to deploy the CosmicPulse backdoor.
The campaign uses compromised websites as part of the delivery infrastructure.
The attacker can then guide the victim toward content designed to initiate the infection.
Once the initial interaction happens, scheduled tasks are used to continue the execution process.
That matters because scheduled tasks provide a native Windows persistence and execution mechanism.
The attacker doesn’t necessarily need a large executable sitting in the user’s Downloads folder.
The operating system already contains everything required to schedule execution.
CosmicPulse is the payload
CosmicPulse is Star Blizzard’s custom backdoor.
Microsoft has tracked the malware in previous campaigns and describes it as part of the actor’s broader post-compromise toolkit.
The purpose is straightforward:
Maintain access.
Communicate with attacker infrastructure.
Run additional commands.
Collect information.
Support follow-on operations.
The phishing email is therefore only the first stage.
The actual objective is persistent access to the endpoint.
The one-interaction problem
This is where the campaign becomes interesting for defenders.
Every additional action required from the victim is another opportunity for detection.
A security warning can interrupt the chain.
The user can become suspicious.
EDR can block the next process.
The browser can prevent a download.
The mail gateway can quarantine an attachment.
The user can simply stop.
RedFlick reduces that friction.
Microsoft says the new flow requires only one user interaction, compared with previous ClickFix-style campaigns that required several actions.
That doesn’t make the underlying malware magically more advanced.
It makes the delivery system more efficient.
Compromised websites are part of the weapon
Microsoft observed Star Blizzard using accounts on compromised websites as part of its operations.
That creates another defensive problem.
Security teams often focus heavily on newly registered malicious domains.
Compromised legitimate infrastructure is harder to classify.
The domain may have existed for years.
It may have a normal reputation.
It may use HTTPS.
It may even belong to a legitimate organization.
The attacker only controls the content being served.
This is why domain reputation alone cannot be treated as a security boundary.
A legitimate website can become malicious infrastructure without changing its domain name.
Scheduled tasks are the quiet part
Windows scheduled tasks are completely legitimate.
Administrators use them constantly.
Backup software uses them.
Update mechanisms use them.
Monitoring tools use them.
Enterprise applications use them.
That makes them attractive to attackers.
If a malicious task is created using a convincing name, it can blend into a noisy operating system.
Defenders should therefore monitor not only the existence of scheduled tasks, but also:
- who created the task
- which process created it
- when it was created
- what executable or script it launches
- where the payload lives
- whether it runs at logon
- whether it contacts an external server
- whether the task appeared shortly after a phishing event
A scheduled task created immediately after a suspicious browser process deserves attention.
Star Blizzard is also changing its phishing infrastructure
Microsoft says the actor has expanded its use of phishing at scale during 2026.
The group has also used compromised accounts and websites to make its operations harder to detect.
That combination creates a layered problem.
The email may look legitimate.
The infrastructure may look legitimate.
The website may be legitimate.
The final payload is still malicious.
This is why modern phishing detection has to connect events instead of judging them individually.
The target list isn’t random
Microsoft says Star Blizzard’s activity has targeted Ukrainian individuals and institutions, international NGOs, Western think tanks, governments and organizations associated with international policy and support for Ukraine.
That targeting pattern is consistent with cyberespionage rather than indiscriminate criminal spam.
For defenders, the practical lesson is that highly targeted phishing doesn’t need to look like mass phishing.
A single carefully written message sent to the right person can be more valuable to an attacker than thousands of generic emails.
The attacker doesn’t need ransomware
There is no requirement for the final payload to encrypt files.
A backdoor can be much more useful.
Once CosmicPulse is running, the attacker can potentially maintain access and decide later what to do.
Credential theft.
Reconnaissance.
Additional malware.
Data collection.
Lateral movement.
Cloud access.
The initial infection is therefore an access operation.
The actual objective may come much later.
Why compromised websites are dangerous
Suppose an employee receives an email containing a link.
The link points to a domain with a long reputation history.
The domain isn’t on the organization’s blocklist.
The TLS certificate is valid.
The site itself isn’t globally malicious.
The attacker has simply compromised one part of it.
Traditional filtering has a problem here.
It sees a website.
The attacker sees a delivery platform.
This is why browser telemetry and endpoint telemetry increasingly matter.
The security team needs to see what happened after the page loaded.
What defenders should monitor
Start with scheduled-task creation.
Look for unusual tasks created by:
- browsers
- Office applications
- scripting engines
- temporary directories
- user profile directories
- unsigned executables
- unusual parent-child process chains
Then inspect outbound connections from those processes.
A newly created scheduled task that launches a script and immediately connects to an unfamiliar external host is a strong investigation candidate.
Also search for CosmicPulse indicators published by Microsoft and compare them against endpoint telemetry.
Email security still matters
The easiest way to stop the attack is still to stop the phishing message.
Organizations should strengthen:
- URL rewriting and analysis
- attachment inspection
- sender authentication
- impersonation protection
- external sender warnings
- browser isolation where appropriate
- endpoint application controls
But email filtering alone isn’t enough.
The campaign deliberately abuses infrastructure that may not initially look malicious.
User training has a limit
Security awareness training still matters.
But the industry should stop pretending that every successful phishing attack is simply the user’s fault.
Attackers are optimizing the workflow.
They study what causes users to stop.
They remove unnecessary steps.
They compromise legitimate websites.
They improve the delivery chain.
They automate the boring parts.
A user who makes one wrong click should not automatically receive unrestricted access to the endpoint.
Security architecture should assume that someone eventually clicks.
The bigger lesson
RedFlick is interesting because it doesn’t require a revolutionary exploit.
There is no new operating-system vulnerability here.
No spectacular RCE.
No kernel escape.
No exotic malware loader.
Instead, Star Blizzard is optimizing a familiar attack.
Phishing.
Compromised websites.
Scheduled tasks.
Backdoor.
Persistence.
The innovation is in the workflow.
Fewer victim actions mean fewer opportunities for the defender to interrupt the chain.
Bugstoday opinion
The best phishing attack isn’t the one with the fanciest malware.
It’s the one that gives the victim almost nothing to notice.
Star Blizzard appears to understand that.
RedFlick reduces the number of decisions the victim has to make while moving more of the infection process into compromised infrastructure and native Windows mechanisms.
That is exactly where defenders need to focus.
Don’t ask only:
“Did the user click?”
Ask:
“What happened during the next 30 seconds?”
That is where the compromise lives.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- Microsoft Threat Intelligence — Star Blizzard refines phishing and malware delivery with the RedFlick technique
- Microsoft Threat Intelligence — Star Blizzard / SEABORGIUM actor profile
- Microsoft Defender — Star Blizzard detections and hunting guidance
- Microsoft Threat Intelligence — CosmicPulse malware analysis




