Star Blizzard RedFlick and CosmicPulse: Sentinel Hunt

Threat Overview

Microsoft Threat Intelligence disclosed on September 29, 2026 that Russian state actor Star Blizzard has used a new one-click malware-delivery technique, RedFlick, during at least 13 larger phishing campaigns since January. The activity affected more than 100 organizations, primarily in the United States and United Kingdom, and targeted Ukrainian entities, NGOs, think tanks, governments, financial organizations, academia, media, and policy organizations. Microsoft directly observed at least one RedFlick scheduled task deploy CosmicPulse, a Python backdoor. Initial messages often contain no attachment and impersonate a trusted person or event organizer. After a recipient replies, the actor sends a password-protected RAR or ZIP containing an LNK disguised as a PDF. Observed chains used VHDX files, conhost.exe, cmd.exe, curl, ssh.exe with PermitLocalCommand, MSI installers, remote CPL execution, WebDAV UNC paths, and three scheduled tasks named Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor. CosmicPulse stores an encrypted key under HKCU\Software\Classes\.mollis and uses packaged Python components. Microsoft also reports continued Evilginx credential and session-cookie phishing.

References

Impacted Systems

  • Platform: Windows endpoints and user mailboxes; vulnerable Apple iOS devices were targeted in a separate DarkSword branch, but this hunt focuses on the confirmed Windows RedFlick chain.
  • Environment: Organizations associated with Ukraine policy or support, government, NGOs, think tanks, finance, academia, media, and technology; the email and endpoint behaviors are applicable more broadly.
  • Prerequisite: User engagement with a lure followed by opening a password-protected archive and disguised LNK; credential-phishing branches may instead capture passwords or session cookies.
  • Components abused: Outlook/email, Windows LNK/VHDX handling, conhost.exe, cmd.exe, curl.exe, ssh.exe, Windows Installer, Task Scheduler, WebDAV/WebClient, control.exe, and Python.
  • Product versions: No vulnerable Windows version is specified. Exposure is behavioral rather than version-bound.
  • Network: Outbound HTTP/HTTPS, WebDAV-style UNC retrieval, and campaign infrastructure listed by Microsoft.

Why this matters

RedFlick reduces the infection chain to one user action and supports persistent espionage through a custom backdoor. The campaign combines high-quality social engineering, compromised legitimate websites, scheduled-task persistence, living-off-the-land binaries, remote payload execution, and session theft. These behaviors are visible across common Microsoft Sentinel email, endpoint, registry, and network telemetry.

Exploitation Status

This is confirmed threat activity, not a proof of concept. Microsoft observed more than 100 organizations affected and at least one endpoint on which a RedFlick task deployed CosmicPulse. Microsoft attributes Star Blizzard to the Russian FSB’s Centre 18 based on government reporting. Published hashes, domains, IPs, task names, registry paths, and process patterns are confirmed observations, but the list is not exhaustive and infrastructure can change.

What this hunt looks for

Published hashes and infrastructure, the RedFlick scheduled-task trio, conhost-to-curl execution, SSH PermitLocalCommand abuse, remote CPL and WebDAV execution, the CosmicPulse .mollis registry artifact, event-invitation email sequences, rare destinations, and Windows event fallback activity.

Required logs

Microsoft Defender for Endpoint DeviceFileEvents, DeviceProcessEvents, DeviceRegistryEvents, and DeviceNetworkEvents; Microsoft 365 Defender EmailEvents and EmailAttachmentInfo; normalized network or ASIM telemetry; and Windows Security Event 4688 with command-line auditing for fallback coverage.

Hunt 1 — Published file hashes and network indicators

let Hashes=dynamic(["9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b","1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d","699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9","24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7","dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4"]);
let IPs=dynamic(["103.245.231.248","2.57.241.246","89.125.209.168","103.245.231.79","45.84.59.66","103.160.59.97"]);
let Domains=dynamic(["etia.ca","groy.cc","gliderrompercycl.com","muvb.net","divekickspolic.org","matjk.click","bpdaersa.click","stuseamandesilt.org","itechx.tel","guach.net","ruten.observer","byveo.org","secure-dns-hub.com","qumel.link","cyrna.top","drasw.club"]);
union isfuzzy=true
(DeviceFileEvents | where TimeGenerated > ago(90d) and SHA256 in (Hashes) | project TimeGenerated,DeviceName,Evidence="File",Detail=strcat(FolderPath,"\\",FileName),SHA256,Account=InitiatingProcessAccountName),
(DeviceNetworkEvents | where TimeGenerated > ago(90d) and (RemoteIP in (IPs) or RemoteUrl has_any (Domains)) | project TimeGenerated,DeviceName,Evidence="Network",Detail=strcat(RemoteUrl," ",RemoteIP,":",RemotePort),SHA256=InitiatingProcessSHA256,Account=InitiatingProcessAccountName)
| order by TimeGenerated desc

Hunt 2 — RedFlick scheduled-task names across process and registry telemetry

let Names=dynamic(["Internet Quality Test Connection","Network Configuration Manager","System Health Monitor"]);
union isfuzzy=true
(DeviceProcessEvents | where TimeGenerated > ago(90d) | where ProcessCommandLine has_any (Names) or InitiatingProcessCommandLine has_any (Names) | project TimeGenerated,DeviceName,Source="Process",ActionType,Detail=ProcessCommandLine,Account=AccountName),
(DeviceRegistryEvents | where TimeGenerated > ago(90d) | where RegistryKey has_any (Names) or RegistryValueName has_any (Names) or RegistryValueData has_any (Names) or InitiatingProcessCommandLine has_any (Names) | project TimeGenerated,DeviceName,Source="Registry",ActionType,Detail=strcat(RegistryKey," ",RegistryValueName," ",RegistryValueData),Account=InitiatingProcessAccountName)
| order by TimeGenerated desc

Hunt 3 — conhost invoking curl in the PDF delivery chain

DeviceProcessEvents
| where TimeGenerated > ago(90d)
| where FileName =~ "conhost.exe" and ProcessCommandLine has "curl"
| project TimeGenerated,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine,SHA256
| order by TimeGenerated desc

Hunt 4 — SSH PermitLocalCommand execution used to retrieve MSI payloads

DeviceProcessEvents
| where TimeGenerated > ago(90d)
| where FileName =~ "ssh.exe" or ProcessCommandLine has "ssh.exe"
| where ProcessCommandLine has "PermitLocalCommand=yes" and ProcessCommandLine has "LocalCommand=cmd.exe"
| project TimeGenerated,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine,SHA256
| order by TimeGenerated desc

Hunt 5 — Remote CPL or WebDAV execution through control.exe

DeviceProcessEvents
| where TimeGenerated > ago(90d)
| where FileName =~ "control.exe" or ProcessCommandLine has "Control_RunDLL"
| where ProcessCommandLine has_any ("\\\\","http://","https://",".cpl")
| project TimeGenerated,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine,SHA256
| order by TimeGenerated desc

Hunt 6 — CosmicPulse encrypted-key registry artifact

DeviceRegistryEvents
| where TimeGenerated > ago(90d)
| where RegistryKey endswith @"\Software\Classes\.mollis" or RegistryValueName =~ ".mollis" or RegistryValueData has @"\Software\Classes\.mollis"
| project TimeGenerated,DeviceName,ActionType,RegistryKey,RegistryValueName,RegistryValueData,InitiatingProcessAccountName,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by TimeGenerated desc

Hunt 7 — Known archive names and disguised LNK/VHDX staging

DeviceFileEvents
| where TimeGenerated > ago(90d)
| where FileName in~ ("Documents.zip","Documents.vhdx","Chatham_London_Conference_2026_Invitation.rar","USUBC_Private_Executive_Roundtable_Webex.rar","Payment Advice Note.zip") or FileName endswith ".vhdx" or FileName endswith ".lnk"
| where FolderPath has_any ("\\Downloads","\\Desktop","\\Temp","\\AppData\\Local\\Temp") or SHA256 in ("9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b","1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d","699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9","24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7","dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4")
| project TimeGenerated,DeviceName,ActionType,FolderPath,FileName,SHA256,InitiatingProcessAccountName,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by TimeGenerated desc

Hunt 8 — Event-invitation lures followed by archive attachments

let LureMail=EmailEvents
| where TimeGenerated > ago(90d)
| where Subject has_any ("Private Roundtable","Closed-Door Discussion","Strategic Discussion","Future of Peace Operations","Future of Liberty","Chatham House","MAMA Summit","Payment Advice Note","tax audit","water supply")
| project MailTime=TimeGenerated,NetworkMessageId,RecipientEmailAddress,SenderFromAddress,SenderFromDomain,Subject,DeliveryAction,ThreatTypes;
EmailAttachmentInfo
| where TimeGenerated > ago(90d) and FileName matches regex @"(?i)\.(zip|rar|vhdx|lnk)$"
| join kind=inner LureMail on NetworkMessageId
| project MailTime,RecipientEmailAddress,SenderFromAddress,SenderFromDomain,Subject,FileName,SHA256,DeliveryAction,ThreatTypes
| order by MailTime desc

Hunt 9 — Rare or newly observed destinations contacted by the RedFlick toolchain

let Baseline=DeviceNetworkEvents
| where TimeGenerated between (ago(90d)..ago(7d))
| summarize by DeviceId,RemoteUrl,RemoteIP;
DeviceNetworkEvents
| where TimeGenerated > ago(7d) and ActionType == "ConnectionSuccess"
| where InitiatingProcessFileName in~ ("conhost.exe","curl.exe","ssh.exe","control.exe","msiexec.exe","python.exe","pythonw.exe")
| join kind=leftanti Baseline on DeviceId,RemoteUrl,RemoteIP
| summarize FirstSeen=min(TimeGenerated),LastSeen=max(TimeGenerated),Connections=count(),RemotePorts=make_set(RemotePort,20),Processes=make_set(InitiatingProcessFileName,20),Commands=make_set(InitiatingProcessCommandLine,10) by DeviceName,RemoteUrl,RemoteIP
| order by Connections desc

Hunt 10 — Windows Security Event fallback for RedFlick execution patterns

SecurityEvent
| where TimeGenerated > ago(90d) and EventID == 4688
| where CommandLine has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor","PermitLocalCommand=yes","LocalCommand=cmd.exe","Control_RunDLL","Software\\Classes\\.mollis") or (NewProcessName endswith "\\conhost.exe" and CommandLine has "curl")
| project TimeGenerated,Computer,SubjectUserName,NewProcessName,ParentProcessName,CommandLine
| order by TimeGenerated desc

Detection Notes

  • Hunts 1, 2, 4, and 6 are highest signal. A known hash or infrastructure match, the exact task-name trio, the SSH option combination, or .mollis registry artifact warrants immediate investigation.
  • Hunt 3 can match legitimate scripted downloads; validate the parent process, URL, downloaded file, user context, and adjacent archive/LNK activity.
  • Event subjects and attachment names changed across campaigns. Hunt 8 is a lead generator and will not detect every lure.
  • Password-protected archives reduce mail-scanning visibility. Email delivery telemetry may show the attachment without its internal LNK or VHDX.
  • Microsoft endpoint queries were translated to Sentinel TimeGenerated; environments using Defender Advanced Hunting directly may need Timestamp instead.
  • Without email, endpoint process, registry, and outbound network telemetry, Sentinel cannot reconstruct the full RedFlick chain.