bleeping-computer · Crawled Oct 1, 2026
Russian state hackers use new RedFlick technique to push malware
3 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
Russian state actor Star Blizzard has been using a new malware delivery technique called 'RedFlick' to deploy the CosmicPulse backdoor. The attack begins with a phishing email containing a password-protected archive with a malicious VHDX file and an LNK shortcut disguised as a PDF. Upon execution, it creates multiple scheduled tasks to evade detection and downloads a Control Panel applet (.cpl) payload named NOROBOT or BAITSWITCH, which fetches and executes the final backdoor. The campaign has targeted Ukrainian entities and international organizations supporting Ukraine, with over 100 organizations impacted since early 2026.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 13 techniques
T1012 Query Registry · Discovery T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1087.002 Domain Account · Discovery T1105 Ingress Tool Transfer · Command And Control T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1204.002 Malicious File · Execution