Threat Overview
Microsoft Threat Intelligence disclosed on September 29, 2026 that Russian state actor Star Blizzard has used a new one-click malware-delivery technique, RedFlick, during at least 13 larger phishing campaigns since January. The activity affected more than 100 organizations, primarily in the United States and United Kingdom, and targeted Ukrainian entities, NGOs, think tanks, governments, financial organizations, academia, media, and policy organizations. Microsoft directly observed at least one RedFlick scheduled task deploy CosmicPulse, a Python backdoor. Initial messages often contain no attachment and impersonate a trusted person or event organizer. After a recipient replies, the actor sends a password-protected RAR or ZIP containing an LNK disguised as a PDF. Observed chains used VHDX files, conhost.exe, cmd.exe, curl, ssh.exe with PermitLocalCommand, MSI installers, remote CPL execution, WebDAV UNC paths, and three scheduled tasks named Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor. CosmicPulse stores an encrypted key under HKCU\Software\Classes\.mollis and uses packaged Python components. Microsoft also reports continued Evilginx credential and session-cookie phishing.
References
- Microsoft Security Blog — Star Blizzard refines phishing and malware delivery with the RedFlick technique — September 29, 2026.
- The Hacker News — Russia’s Star Blizzard Targets 100+ Organizations With Fake Event Invites — September 29, 2026.
Impacted Systems
- Platform: Windows endpoints and user mailboxes; vulnerable Apple iOS devices were targeted in a separate DarkSword branch, but this hunt focuses on the confirmed Windows RedFlick chain.
- Environment: Organizations associated with Ukraine policy or support, government, NGOs, think tanks, finance, academia, media, and technology; the email and endpoint behaviors are applicable more broadly.
- Prerequisite: User engagement with a lure followed by opening a password-protected archive and disguised LNK; credential-phishing branches may instead capture passwords or session cookies.
- Components abused: Outlook/email, Windows LNK/VHDX handling,
conhost.exe,cmd.exe,curl.exe,ssh.exe, Windows Installer, Task Scheduler, WebDAV/WebClient,control.exe, and Python. - Product versions: No vulnerable Windows version is specified. Exposure is behavioral rather than version-bound.
- Network: Outbound HTTP/HTTPS, WebDAV-style UNC retrieval, and campaign infrastructure listed by Microsoft.
Why this matters
RedFlick reduces the infection chain to one user action and supports persistent espionage through a custom backdoor. The campaign combines high-quality social engineering, compromised legitimate websites, scheduled-task persistence, living-off-the-land binaries, remote payload execution, and session theft. These behaviors are visible across common Microsoft Sentinel email, endpoint, registry, and network telemetry.
Exploitation Status
This is confirmed threat activity, not a proof of concept. Microsoft observed more than 100 organizations affected and at least one endpoint on which a RedFlick task deployed CosmicPulse. Microsoft attributes Star Blizzard to the Russian FSB’s Centre 18 based on government reporting. Published hashes, domains, IPs, task names, registry paths, and process patterns are confirmed observations, but the list is not exhaustive and infrastructure can change.
What this hunt looks for
Published hashes and infrastructure, the RedFlick scheduled-task trio, conhost-to-curl execution, SSH PermitLocalCommand abuse, remote CPL and WebDAV execution, the CosmicPulse .mollis registry artifact, event-invitation email sequences, rare destinations, and Windows event fallback activity.
Required logs
Microsoft Defender for Endpoint DeviceFileEvents, DeviceProcessEvents, DeviceRegistryEvents, and DeviceNetworkEvents; Microsoft 365 Defender EmailEvents and EmailAttachmentInfo; normalized network or ASIM telemetry; and Windows Security Event 4688 with command-line auditing for fallback coverage.
Hunt 1 — Published file hashes and network indicators
let Hashes=dynamic(["9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b","1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d","699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9","24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7","dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4"]);
let IPs=dynamic(["103.245.231.248","2.57.241.246","89.125.209.168","103.245.231.79","45.84.59.66","103.160.59.97"]);
let Domains=dynamic(["etia.ca","groy.cc","gliderrompercycl.com","muvb.net","divekickspolic.org","matjk.click","bpdaersa.click","stuseamandesilt.org","itechx.tel","guach.net","ruten.observer","byveo.org","secure-dns-hub.com","qumel.link","cyrna.top","drasw.club"]);
union isfuzzy=true
(DeviceFileEvents | where TimeGenerated > ago(90d) and SHA256 in (Hashes) | project TimeGenerated,DeviceName,Evidence="File",Detail=strcat(FolderPath,"\\",FileName),SHA256,Account=InitiatingProcessAccountName),
(DeviceNetworkEvents | where TimeGenerated > ago(90d) and (RemoteIP in (IPs) or RemoteUrl has_any (Domains)) | project TimeGenerated,DeviceName,Evidence="Network",Detail=strcat(RemoteUrl," ",RemoteIP,":",RemotePort),SHA256=InitiatingProcessSHA256,Account=InitiatingProcessAccountName)
| order by TimeGenerated desc
Hunt 2 — RedFlick scheduled-task names across process and registry telemetry
let Names=dynamic(["Internet Quality Test Connection","Network Configuration Manager","System Health Monitor"]);
union isfuzzy=true
(DeviceProcessEvents | where TimeGenerated > ago(90d) | where ProcessCommandLine has_any (Names) or InitiatingProcessCommandLine has_any (Names) | project TimeGenerated,DeviceName,Source="Process",ActionType,Detail=ProcessCommandLine,Account=AccountName),
(DeviceRegistryEvents | where TimeGenerated > ago(90d) | where RegistryKey has_any (Names) or RegistryValueName has_any (Names) or RegistryValueData has_any (Names) or InitiatingProcessCommandLine has_any (Names) | project TimeGenerated,DeviceName,Source="Registry",ActionType,Detail=strcat(RegistryKey," ",RegistryValueName," ",RegistryValueData),Account=InitiatingProcessAccountName)
| order by TimeGenerated desc
Hunt 3 — conhost invoking curl in the PDF delivery chain
DeviceProcessEvents
| where TimeGenerated > ago(90d)
| where FileName =~ "conhost.exe" and ProcessCommandLine has "curl"
| project TimeGenerated,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine,SHA256
| order by TimeGenerated desc
Hunt 4 — SSH PermitLocalCommand execution used to retrieve MSI payloads
DeviceProcessEvents
| where TimeGenerated > ago(90d)
| where FileName =~ "ssh.exe" or ProcessCommandLine has "ssh.exe"
| where ProcessCommandLine has "PermitLocalCommand=yes" and ProcessCommandLine has "LocalCommand=cmd.exe"
| project TimeGenerated,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine,SHA256
| order by TimeGenerated desc
Hunt 5 — Remote CPL or WebDAV execution through control.exe
DeviceProcessEvents
| where TimeGenerated > ago(90d)
| where FileName =~ "control.exe" or ProcessCommandLine has "Control_RunDLL"
| where ProcessCommandLine has_any ("\\\\","http://","https://",".cpl")
| project TimeGenerated,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine,SHA256
| order by TimeGenerated desc
Hunt 6 — CosmicPulse encrypted-key registry artifact
DeviceRegistryEvents
| where TimeGenerated > ago(90d)
| where RegistryKey endswith @"\Software\Classes\.mollis" or RegistryValueName =~ ".mollis" or RegistryValueData has @"\Software\Classes\.mollis"
| project TimeGenerated,DeviceName,ActionType,RegistryKey,RegistryValueName,RegistryValueData,InitiatingProcessAccountName,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by TimeGenerated desc
Hunt 7 — Known archive names and disguised LNK/VHDX staging
DeviceFileEvents
| where TimeGenerated > ago(90d)
| where FileName in~ ("Documents.zip","Documents.vhdx","Chatham_London_Conference_2026_Invitation.rar","USUBC_Private_Executive_Roundtable_Webex.rar","Payment Advice Note.zip") or FileName endswith ".vhdx" or FileName endswith ".lnk"
| where FolderPath has_any ("\\Downloads","\\Desktop","\\Temp","\\AppData\\Local\\Temp") or SHA256 in ("9707a8694e954e9ee13e839d6e5905ce626c0837c7c90da6d1025bfbe152866b","1f2096ff906915fbf80778f0636446206197351f7e271af97936eeb6f32c179d","699e92a9e0edf7835879d5697bc67138c0b137117f459caf1a44df357407cad9","24b6e36a09eb2acfc2a95478ca685acb7593b1689be6a4a639fe0d222393cfa7","dd98dbc1a55afe6fd0ed2ed53a79c76f6bde15081a0060422185b74eb1799ee4")
| project TimeGenerated,DeviceName,ActionType,FolderPath,FileName,SHA256,InitiatingProcessAccountName,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by TimeGenerated desc
Hunt 8 — Event-invitation lures followed by archive attachments
let LureMail=EmailEvents
| where TimeGenerated > ago(90d)
| where Subject has_any ("Private Roundtable","Closed-Door Discussion","Strategic Discussion","Future of Peace Operations","Future of Liberty","Chatham House","MAMA Summit","Payment Advice Note","tax audit","water supply")
| project MailTime=TimeGenerated,NetworkMessageId,RecipientEmailAddress,SenderFromAddress,SenderFromDomain,Subject,DeliveryAction,ThreatTypes;
EmailAttachmentInfo
| where TimeGenerated > ago(90d) and FileName matches regex @"(?i)\.(zip|rar|vhdx|lnk)$"
| join kind=inner LureMail on NetworkMessageId
| project MailTime,RecipientEmailAddress,SenderFromAddress,SenderFromDomain,Subject,FileName,SHA256,DeliveryAction,ThreatTypes
| order by MailTime desc
Hunt 9 — Rare or newly observed destinations contacted by the RedFlick toolchain
let Baseline=DeviceNetworkEvents
| where TimeGenerated between (ago(90d)..ago(7d))
| summarize by DeviceId,RemoteUrl,RemoteIP;
DeviceNetworkEvents
| where TimeGenerated > ago(7d) and ActionType == "ConnectionSuccess"
| where InitiatingProcessFileName in~ ("conhost.exe","curl.exe","ssh.exe","control.exe","msiexec.exe","python.exe","pythonw.exe")
| join kind=leftanti Baseline on DeviceId,RemoteUrl,RemoteIP
| summarize FirstSeen=min(TimeGenerated),LastSeen=max(TimeGenerated),Connections=count(),RemotePorts=make_set(RemotePort,20),Processes=make_set(InitiatingProcessFileName,20),Commands=make_set(InitiatingProcessCommandLine,10) by DeviceName,RemoteUrl,RemoteIP
| order by Connections desc
Hunt 10 — Windows Security Event fallback for RedFlick execution patterns
SecurityEvent
| where TimeGenerated > ago(90d) and EventID == 4688
| where CommandLine has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor","PermitLocalCommand=yes","LocalCommand=cmd.exe","Control_RunDLL","Software\\Classes\\.mollis") or (NewProcessName endswith "\\conhost.exe" and CommandLine has "curl")
| project TimeGenerated,Computer,SubjectUserName,NewProcessName,ParentProcessName,CommandLine
| order by TimeGenerated desc
Detection Notes
- Hunts 1, 2, 4, and 6 are highest signal. A known hash or infrastructure match, the exact task-name trio, the SSH option combination, or
.mollisregistry artifact warrants immediate investigation. - Hunt 3 can match legitimate scripted downloads; validate the parent process, URL, downloaded file, user context, and adjacent archive/LNK activity.
- Event subjects and attachment names changed across campaigns. Hunt 8 is a lead generator and will not detect every lure.
- Password-protected archives reduce mail-scanning visibility. Email delivery telemetry may show the attachment without its internal LNK or VHDX.
- Microsoft endpoint queries were translated to Sentinel
TimeGenerated; environments using Defender Advanced Hunting directly may needTimestampinstead. - Without email, endpoint process, registry, and outbound network telemetry, Sentinel cannot reconstruct the full RedFlick chain.