A Russian state-backed hacking group is turning an ordinary Windows feature into part of a more streamlined malware attack.
Microsoft says Star Blizzard has adopted a new malware delivery technique called RedFlick, which uses Windows scheduled tasks to help deploy the CosmicPulse backdoor. The activity has affected more than 100 organizations, primarily in the US and UK, while targeting Ukrainian individuals and institutions as well as international NGOs, think tanks, governments, and financial institutions that have supported Ukraine politically or financially.
The shift matters because Star Blizzard has reduced the amount of work required from victims while using seemingly legitimate Windows tasks for persistence, making suspicious activity potentially harder to distinguish from normal system operations.
RedFlick uses Windows scheduled tasks for persistence
According to Microsoft Threat Intelligence, Star Blizzard has been changing its attack methods throughout 2026 as part of an ongoing cyberespionage operation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) attributes Star Blizzard as subordinate to Russia's Federal Security Service, or FSB, Centre 18. The group has historically relied heavily on targeted social engineering and credential theft.
RedFlick represents a change in how the group delivers malware.
Microsoft observed Star Blizzard change its persistence tactics in April to include RedFlick scheduled tasks. In one version of the attack, a malicious MSI installer creates three scheduled tasks designed to resemble legitimate Windows network or system components:
- Internet Quality Test Connection
- Network Configuration Manager
- System Health Monitor
Each task serves a different function in the infection chain. Microsoft said it observed either the first or third task deploying CosmicPulse in at least one incident.
The approach leverages a legitimate Windows capability commonly used to automatically run programs or scripts at predetermined times or in response to specific events. Attackers can similarly abuse scheduled tasks to execute malicious code and maintain access.
The technique fits a broader pattern of attackers hiding malicious activity inside trusted Windows functionality. Earlier this year, eSecurity Planet reported on a ClickFix campaign abusing PowerShell to install StealC malware after users were tricked by fake CAPTCHA pages.
Star Blizzard cuts the attack down to one user interaction
Microsoft says RedFlick is a departure from Star Blizzard's previous ClickFix-based infection chains, which required victims to perform multiple actions before CosmicPulse could be installed.
With RedFlick, the infection flow can require just one user interaction.
The group has also expanded from exclusively targeted spear-phishing operations to conducting larger-scale campaigns. Microsoft identified at least 13 distinct large-scale phishing campaigns since January 2026, with targeting initially concentrated on Ukraine before expanding internationally.
Phishing lures have included fake conference invitations, payment notices, tax audit warnings, and other documents designed to convince recipients to engage with the attackers.
In many cases, the attackers first contact a target without an attachment. If the recipient responds, a follow-up email typically arrives containing a password-protected RAR or ZIP archive.
Star Blizzard has also begun creating email accounts on compromised legitimate websites rather than relying exclusively on free email providers. Microsoft assesses with high confidence that the group compromised websites hosted on platforms including WordPress and cPanel to support these operations.
That evolution is important because defenders increasingly have to account for attackers abusing infrastructure and workflows users already trust. Similar problems have surfaced in Microsoft environments, including recent passkey-themed phishing attacks targeting Microsoft 365 and campaigns abusing legitimate authentication processes.
Attack chain uses LNK files, PDFs, PowerShell, and MSI installers
RedFlick has not remained static:
- Microsoft documented several versions of Star Blizzard's malware delivery chain between January and August 2026.
- In January, attackers delivered a malicious VHDX file inside a password-protected ZIP archive. The virtual disk contained an LNK file disguised as a PDF, along with a hidden directory containing a BAT script and a legitimate decoy PDF.
- By April, Star Blizzard had expanded its use of scheduled tasks, with a malicious MSI installer creating three tasks for persistence and other functions.
- Then, in July, Microsoft observed another variation that concealed malicious data inside a PDF.
The newer attack chain can involve:
- A phishing email delivering a password-protected archive.
- An LNK file exposed when the archive is opened.
- conhost.exe and curl downloading a PDF from attacker-controlled infrastructure.
- PowerShell extracting Base64-encoded data hidden within the PDF.
- Another command attempting to download and install a malicious MSI package.
- The installer attempting to create additional scheduled tasks.
- A scheduled task attempting to download and execute a malicious Control Panel applet.
The combination of legitimate Windows utilities, disguised files, encoded payloads, and scheduled tasks gives defenders several layers of activity to examine rather than a single malicious executable.
Attackers have increasingly combined Windows and browser or application weaknesses with post-compromise tooling. A separate espionage campaign covered by eSecurity Planet recently showed four spy groups using BlueMoon to chain Chrome and Windows vulnerabilities before deploying malware.
How organizations can detect and block RedFlick attacks
Organizations connected to Ukraine policy or support face the most clearly documented risk from this campaign. Microsoft says organizations most likely at risk are primarily governments, NGOs, or think tanks adjacent to Ukraine policy or support.
Defenders should pay particular attention to the phishing behavior and endpoint activity Microsoft documented.
Microsoft recommends organizations:
- Use phishing-resistant authentication methods.
- Apply Conditional Access policies to restrict suspicious account access.
- Use advanced anti-phishing protections that scan incoming email and visited websites.
- Enable Safe Links and Safe Attachments where available.
- Run endpoint detection and response tools in block mode.
- Keep real-time endpoint protection enabled.
- Monitor for suspicious or anomalous sign-in activity.
- Enable network protections that block access to malicious domains.
- Investigate suspicious LNK execution, unexpected MSI activity, and unusual script activity.
- Examine unfamiliar scheduled tasks, particularly those masquerading as routine network or system management components.
Microsoft Defender includes detections for RedFlick and CosmicPulse, including Trojan/RedFlick, Backdoor/CosmicPulse, and Backdoor/CosmicPulse.
Security teams should also avoid assuming that familiar Windows processes are inherently safe. The RedFlick campaign shows how attackers can weave malicious execution through built-in tools and normal-looking system components rather than relying on an obviously suspicious executable.
Why RedFlick matters for Windows defenders
RedFlick's most important lesson is not simply that attackers can create malicious scheduled tasks. That technique is well established. The bigger concern is how Star Blizzard is combining trusted Windows components, compromised legitimate infrastructure, convincing phishing lures, and fewer required user actions into a more streamlined infection chain.
For security teams, that shifts some of the defensive burden from spotting a clearly malicious file to identifying unexpected behavior from legitimate Windows tools. Monitoring scheduled task creation, PowerShell activity, LNK execution, MSI installations, and outbound connections together can provide more context than treating any single event in isolation.
Organizations in Star Blizzard's documented target set should pay particular attention to that behavior. But the broader defensive takeaway applies well beyond this campaign: when attackers increasingly hide inside legitimate Windows functionality, understanding what is normal on an endpoint becomes just as important as recognizing known malware.
Also read: CLOSEDQUORUM Malware Lets AI Models Vote on Credential Theft — What Defenders Can Detect for another recent Windows malware campaign focused on persistence, credential theft, and post-compromise activity.





