DEV Community

Anoymask
Anoymask

Posted on

Star Blizzard: RedFlick Uses Scheduled Tasks to Deploy CosmicPulse

1. Overview

  • Report Title: Star Blizzard refines phishing and malware delivery with the RedFlick technique
  • Source: Microsoft Threat Intelligence
  • Publication Date: 2026-09-29
  • Original Reference: Microsoft Threat Intelligence
  • Related References: Google Threat Intelligence: COLDCOPY / CosmicPulse, CISA advisory AA23-341A
  • Associated Malware, Threat Groups, CVEs, and Products: CosmicPulse, RedFlick, NOROBOT, BAITSWITCH, YESROBOT, DarkSword, Star Blizzard, SEABORGIUM, Windows, Microsoft Defender
  • Severity: High (At least 13 large-scale campaigns and impacts on over 100 organizations were observed in 2026, utilizing a chain that requires fewer user interactions than ClickFix to achieve persistence and deploy a backdoor.)

2. Executive Summary

Star Blizzard has adopted a new technique called "RedFlick," combining email accounts on compromised websites with large-scale phishing to deploy the CosmicPulse backdoor via scheduled tasks initiated by LNK file execution. Microsoft's definition of "one-click" refers to the deployment sequence triggered after executing the malicious LNK file, and does not mean that actions such as replying to emails or extracting archives are unnecessary. The January pathway utilizing VHDX and the July pathway extracting a Base64 payload from a PDF represent distinct campaign configurations.

3. Attack Flow

RedFlick Distribution and CosmicPulse Deployment by Period

  1. Attackers use email accounts on compromised websites or free webmail services to send initial contact emails disguised as meeting invitations, tax notifications, fine notices, or invoices to targets.
  2. Typically, targets who reply to the email are sent a password-protected ZIP or RAR archive containing an LNK file to execute (in the January case, an LNK disguised as a PDF was placed inside a VHDX within a ZIP; in the July case, an LNK was extracted from a password-protected RAR inside a ZIP).
  3. In the January attack chain, execution proceeds in the order of LNK -> conhost.exe -> cmd.exe -> BAT, abusing the PermitLocalCommand feature of ssh.exe to retrieve and execute a remote MSI file. Meanwhile, in the July attack chain, an LNK retrieves a PDF via curl, and PowerShell extracts and decodes Base64 data from that PDF, then executes a command that attempts to download and execute an MSI. This is not execution triggered by viewing the PDF normally.
  4. The execution of the MSI creates scheduled tasks. The January configuration created one task, while the April configuration created three tasks disguised as legitimate network components (the later July phase attempted to create two additional tasks for helper and CPL retrieval/execution). One of the tasks in April acted as an auxiliary for retrieving a remote payload via WebDAV/WebClient, and not all three tasks executed downloaders.
  5. Downloaders launched by the tasks retrieve the Python runtime and the encrypted CosmicPulse payload. The bootstrapper reads the encrypted AES key from HKCU\Software\Classes\.mollis and recovers it using an embedded key in AES-ECB mode. It then uses the recovered key to decrypt the payload before execution.
Observation Period Distribution and Initial Execution Chain Intermediate Retrieval and Task Configuration Final Payload and Persistence
January 2026 Campaign Executed a BAT file from a PDF-disguised LNK contained within a VHDX inside a password-protected ZIP Abused ssh.exe's PermitLocalCommand to retrieve and execute a remote MSI. Created one task Deploys the Python runtime and encrypted CosmicPulse payload; the bootstrapper recovers the AES key stored in encrypted form under .mollis and uses it to decrypt the payload
April 2026 Campaign Deployed via LNK and MSI from phishing emails Created three scheduled tasks disguised as legitimate network components (Task 2 served as a WebDAV/WebClient auxiliary) Microsoft observed either Task 1 or Task 3 deploying CosmicPulse in at least one incident; Microsoft did not obtain the DLL sample referenced by Task 1
July 2026 Campaign Executed LNK from a password-protected RAR within a ZIP. Retrieved a PDF externally via curl PowerShell extracts and decodes Base64 data from the PDF, then runs a command that attempts MSI retrieval and execution; a later stage attempts to create two additional helper and CPL retrieval/execution tasks Attempted to retrieve and execute a CPL-type downloader, aiming to deploy CosmicPulse

4. Attacker Infrastructure and Execution Location

  • Attackers control email delivery infrastructure and external hosting servers, typically sending password-protected archives after confirming a reply from the target (campaigns attaching lures directly to the initial email without a reply have also been observed).
  • Payloads execute on the target's Windows endpoint, with scheduled tasks and a Python-based backdoor handling local persistence and C2 communication.

5. Victim and Administrator Perspective

Victims

  • In reply-based campaigns, targets receive a password-protected archive after responding to an invitation or notice. The archive exposes a malicious shortcut, which may be disguised as a PDF. In the January VHDX chain, the BAT script opens a decoy PDF, potentially distracting the user from the malicious activity.

Administrators

  • Observable indicators include unnatural bulk email transmissions from legitimate domains, VHDX/LNK files inside archives, curl launches from conhost, execution of ssh.exe with the PermitLocalCommand option, installer execution via msiexec, suspicious scheduled task registrations, CPL execution via control.exe, and the spawning of Python processes.

6. Success and Failure Conditions

Success Conditions

  • The target user extracts the received archive and manually executes the shortcut (LNK) or similar files. While the flow of sending an archive after a reply is typical, a reply itself is not an absolute prerequisite across all campaigns.
  • The components used in the relevant variant must run without being blocked. These include the January ssh.exe pathway or the July PowerShell pathway, followed by the applicable MSI, scheduled task, CPL, and Python stages. The April WebDAV pathway also requires functioning WebClient support and access to the remote payload over HTTP/HTTPS.
  • Communications destined for external hosting infrastructure and the CosmicPulse C2 server must be reachable over the network.

Failure Conditions and Risk Mitigation

  • Quarantine and isolate password-protected archives attached to reply emails at the gateway, and enforce policies prohibiting the execution of LNK or VHDX files originating from email.
  • Enforce application control and EDR blocking for ssh.exe PermitLocalCommand argument specifications, remote CPL execution via control.exe, suspicious scheduled task creation, and Python payloads running under user profiles.
  • Implement phishing-resistant MFA (such as FIDO2) to reduce the risk of credential theft in separate campaigns escalating to Account Takeover (ATO).

7. What Happens Upon Success

  • The CosmicPulse backdoor establishes persistence on the Windows endpoint, creating a robust foothold to receive remote commands from the attacker.
  • Email accounts on compromised legitimate domains are abused as delivery infrastructure for further large-scale phishing attacks.
  • While Microsoft reported impacts on over 100 organizations, it does not explicitly state that backdoor execution succeeded across all of them.

8. Observable Logs

  • Email: Scrutinize initial contact emails and their reply threads, subsequent deliveries of password-protected ZIP/RAR files, senders reusing the same local-part across multiple compromised domains, and short-duration bulk delivery logs.
  • Proxy / SWG / DNS: Check retrieval logs for MSI, CPL, and ZIP files across various pathways, along with communications destined for CosmicPulse-related domains and IPs. ssh.exe acts as a trigger for local command execution, and CPL retrieval also includes HTTP/HTTPS traffic via WebDAV/WebClient. Since proxies and DNS alone cannot identify the launching process, they must always be correlated with EDR telemetry.
  • Endpoint / EDR: Confirm the LNK -> conhost / cmd / BAT process tree, ssh.exe PermitLocalCommand arguments, msiexec activity, control.exe arguments, new task registrations, Python execution, and writes to the registry (.mollis).
  • Identity / IdP: Audit campaign-related account sign-ins, anomalous MFA events, and the creation and sending logs of new email accounts on compromised websites.
  • SaaS / Cloud: Check mailbox forwarding rules, message traces, outbound traffic volumes, security alerts, and Defender detection logs.
  • Network: Investigate communications from endpoints to external payload hosts and CosmicPulse C2 servers.

9. Attack Success Assessment

  • Initial Execution Confirmed: Public information: Microsoft observed RedFlick execution chains and scheduled tasks, including at least one incident in which either Task 1 or Task 3 deployed CosmicPulse. The later July stages are described as attempts to retrieve and execute an MSI and create additional tasks. These findings do not establish successful backdoor deployment in every one of the more than 100 affected organizations. (Scope: the 2026 campaigns observed by Microsoft)

10. Investigation Playbook

  • Investigation Origin: Initiate investigations upon detecting the receipt of password-protected archives, LNK file execution, ssh.exe PermitLocalCommand, or suspicious task name registration alerts.
  • Initial Verification: Identify and preserve email thread history, presence of replies, legitimacy of sender domains, attachment hashes, deployed file structures, and user action timestamps.
  • Endpoint and Server Investigation: Forensically preserve LNK, BAT, PDF, PowerShell scripts, MSI, CPL, Python files, registry keys, task definition XMLs, and downloaded temporary files.
  • Authentication and Cloud Investigation: Investigate mailbox sign-in history, sending account status, MFA registration status, email flow rules, and suspicious OAuth application integrations.
  • Tracking Subsequent Activity: Track CosmicPulse C2 communications, credential access, lateral movement, and internal data collection/staging activities.
  • Containment: Logically isolate infected endpoints from the network, completely remove registered tasks and malicious payloads, revoke credentials and sessions for related accounts, and broadly deploy extracted IOCs to security appliances.
  • Assessment Categories: Strictly differentiate and record the stages of email contact, replies, attachment execution, downloader initiation, backdoor establishment, and subsequent activities.

11. Defense and Detection Ideas

  • Single Events: Detect ssh.exe command lines containing PermitLocalCommand=yes and LocalCommand=cmd.exe, remote CPL execution through control.exe, and characteristic scheduled task registrations. Investigate the surrounding context before treating a match as malicious, and block confirmed malicious activity.
  • Timeline Correlation: Correlate the chain of email contact (with replies depending on the pathway) -> archive opening -> LNK execution -> remote downloads per pathway -> MSI/task registration -> Python execution and C2 communication chronologically (independently verifying evidence of success at each stage).
  • Threat Hunting: Hunt cross-organizationally for characteristic task names such as Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor, as well as the registry .mollis key.
  • Log Limitations: Without preserved internal structures of encrypted archives, email body threads, full process command-line arguments, and task registration XML definitions, the full picture of the attack chain cannot be reconstructed.
  • Priority Mitigations: Prioritize deploying dynamic sandbox analysis for attachments, robust application control, mandatory phishing-resistant MFA, EDR block-mode operation, and strict egress filtering.

12. Facts / Inference / Hypothesis

Facts

  • Microsoft observed that beginning in January 2026, Star Blizzard deployed initial contact phishing campaigns consisting of dozens to hundreds of emails per campaign, alongside traditional targeted spear-phishing.
  • At least 13 large-scale campaigns were confirmed, impacting over 100 organizations including NGOs, think tanks, government agencies, and financial institutions primarily in the US and UK, as well as Ukraine-related entities.
  • Attackers created identical account names across multiple website domains hosted on cPanel and WordPress to use for sending emails. Microsoft assesses with high confidence that these sites were compromised by Star Blizzard for this purpose.
  • In the January attack chain, a PDF-disguised LNK and a BAT file were placed inside a VHDX within a password-protected ZIP, abusing ssh.exe PermitLocalCommand to download and execute a remote MSI.
  • The April configuration created three scheduled tasks disguised as legitimate network components. Task 2 supported WebDAV-based execution. Microsoft observed either Task 1 or Task 3 deploying CosmicPulse in at least one incident, but did not obtain the DLL sample referenced by Task 1.
  • In the July attack chain, an LNK retrieved a PDF via curl, and PowerShell extracted and decoded embedded Base64 data to execute commands and attempt MSI retrieval/execution. A later phase attempted to create two additional tasks for helper and CPL retrieval/execution.

Inference

  • The scaling up of campaigns and reduction of user interaction indicate that Star Blizzard has shifted toward an operational model that expands opportunities for successful attacks while maintaining traditional targeting criteria.
  • Sending emails from compromised legitimate domains weakens permission decisions relying solely on domain reputation, necessitating composite detection that combines contextual analysis, sender behavioral baselines, archive structures, and child process behaviors.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "14. Open Questions and Additional Research".

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1566.001 Phishing: Spearphishing Attachment high A distribution chain sending password-protected archives after email replies has been confirmed.
T1204.002 User Execution: Malicious File high Manual execution of shortcuts (LNK) disguised as PDFs or similar files is required.
T1053.005 Scheduled Task/Job: Scheduled Task high The three tasks reported by Microsoft in April served execution and WebDAV auxiliary roles; identical configurations were not used across all periods.
T1218.002 System Binary Proxy Execution: Control Panel high Proxy-executes CPL-format downloaders via control.exe.
T1105 Ingress Tool Transfer high Acquires MSIs, CPLs, Python packages, and CosmicPulse payloads from external infrastructure.

14. Open Questions and Additional Research

  • How many of the more than 100 affected organizations experienced successful malware execution, and how many experienced credential theft.
  • Whether data was collected or exfiltrated after CosmicPulse execution, what data was involved, and which C2 commands were issued.
  • The initial intrusion methods that led to the creation of unauthorized accounts on compromised websites.

15. Impact on SOCs and Organizations

Organizations involved in diplomacy, national security, support for Ukraine, advanced research, civil society, or finance should treat unexpected password-protected archives as high-risk, including those received after replying to invitations or billing notices from legitimate domains. After LNK execution, SOCs should distinguish January's BAT/ssh.exe chain from July's PDF retrieval and PowerShell extraction chain. Correlation should follow the MSI, scheduled task, CPL, and CosmicPulse activity relevant to each variant. Requiring every element from all periods to appear together can cause detection rules to miss a valid attack chain.

16. Summary by Target Audience

  • For SOCs: Track the flow from initial contact emails to archive receipt and LNK execution, cross-correlating the period-specific ssh.exe or PDF/PowerShell pathways with subsequent task and CosmicPulse behaviors.
  • For Administrators: Promote rigorous phishing-resistant MFA, enable Safe Attachments/Safe Links, operate EDR in block mode, and thoroughly inspect archives even for emails originating from legitimate domains.
  • For Users: Even if communications come from actual business partners or legitimate domains, verify authenticity using known secure communication channels before opening password-protected ZIP/RAR files received after replying.

Top comments (0)