The actor has lowered the amount of victim interaction required

Microsoft says Star Blizzard has moved beyond earlier ClickFix-style infection chains and now uses a technique it calls RedFlick to deliver its CosmicPulse backdoor. The reported flow requires a single user interaction after a phishing exchange, rather than several manual steps, and Microsoft observed it alongside a broader shift toward higher-volume phishing.

Microsoft reports that campaigns since January targeted Ukrainian organisations and people, plus NGOs, think tanks, governments, and financial institutions associated with support for Ukraine. The company says the activity affected more than 100 organisations, primarily in the United States and United Kingdom.

Treat the chain as a behavior set, not a single signature

The components Microsoft describes—archives, LNK files, scheduled tasks, WebDAV, control.exe, and PowerShell—also have legitimate uses. Alert on suspicious combinations, provenance, timing, and remote destinations rather than blocking any one utility in isolation.

A reply to a trusted-looking contact can start the sequence

  • An initial phishing message impersonates an expected contact, often with no attachment. A reply is followed by a password-protected ZIP or RAR archive.
  • Observed lures include VHDX content and LNK files disguised as PDFs. The chain can open a decoy while executing hidden commands.
  • Microsoft observed a downloader masquerading as a Control Panel applet, then installation of the CosmicPulse Python backdoor.
  • The persistence stage uses scheduled tasks with plausible names, including Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.
  • One task supports WebDAV access and others beacon or retrieve next-stage content. Microsoft also observed payload data concealed inside a PDF in a later delivery variant.

Join email, endpoint, and network evidence

  • Investigate password-protected archives that arrive after an earlier conversation, especially where the password is presented as an image or the sender uses a lookalike identity.
  • Hunt for LNK execution from archives or mounted VHDX files, particularly where the visible filename or icon suggests a PDF.
  • Review conhost.exe, cmd.exe, ssh.exe, curl.exe, msiexec.exe, control.exe, and PowerShell as a process chain rather than in isolation.
  • Search scheduled-task creation and modification for the three names Microsoft published, and inspect associated command lines, creators, triggers, and network activity.
  • Review WebDAV-style UNC access, WebClient activity, unusual outbound HTTP or HTTPS from user workstations, and the registry path HKCU\\Software\\Classes\\.mollis in context of the reported installer behavior.

Verify the sender outside the email thread

  1. 1

    Protect likely targets. Use phishing-resistant authentication, conditional access, and enhanced mail protections for policy, research, NGO, government, and Ukraine-related roles—not only executives.

  2. 2

    Make archive delivery visible. Quarantine or add review controls for password-protected archives and deceptive shortcuts where business workflows permit. Preserve the originating message and the full attachment chain.

  3. 3

    Contain on correlated evidence. Isolate a device when the phishing, execution, scheduled-task, and network signals align. Collect volatile and endpoint evidence before cleaning whenever feasible.

  4. 4

    Remove persistence and recover accounts. Delete confirmed malicious tasks and payloads, block validated infrastructure, rotate credentials exposed to the device, and review mailbox rules and cloud sign-ins.

A trusted-looking conversation is now part of the attack surface

The useful control is not simply “block ZIP files.” RedFlick depends on social context: the attacker establishes contact, receives engagement, then sends a follow-up that appears expected. Train high-risk teams to verify a contact using a known channel before opening an archive, and make endpoint telemetry capable of connecting that decision to later execution.