The RedFlick Malware attack begins with something ordinary: an invitation arriving in an inbox. Then another message appears, carrying a password protected ZIP or RAR archive. Nothing about that opening scene screams espionage. That is precisely the point.
Star Blizzard, a Russian state hacking group active since 2017, now uses a delivery tactic called RedFlick to install its CosmicPulse backdoor. The tactic does not introduce a revolutionary new hacking idea. Instead, it rearranges familiar parts into a smoother, more automated process that demands less interaction from the victim.
Inside the archive sits a VHDX virtual disk. Most people will never think about a virtual disk, and attackers count on that indifference. The disk contains an LNK file, which looks like a PDF document. When the victim opens it, the file launches a command in a hidden window while displaying a harmless looking PDF as a decoy.
That small performance matters. The victim sees a document, not a command shell. A click produces something familiar, perhaps even boring, while the real activity continues out of sight. The attack borrows the oldest trick in computing security: make the dangerous action resemble an administrative routine.
The command downloads and runs an MSI installer. Windows uses MSI packages for software installation, so the file can blend into a normal business environment. The installer then creates three scheduled tasks that pose as legitimate maintenance components. Scheduled tasks allow Windows to run programs at selected times or under selected conditions. For an attacker, they offer a quiet way to keep malware active without asking the victim to click again.
That design shows RedFlick’s real value. Star Blizzard has not discovered a magic doorway into every computer. It has reduced friction. The group can guide a victim through one convincing moment, then let the machine carry out more of the sequence.
Why this matters beyond one malware campaign
Star Blizzard has a record of testing different ways to deliver malicious software, including ClickFix and WhatsApp based approaches. Its latest move reflects a broader shift in phishing. Attackers increasingly treat the email as only the opening scene. The payload, persistence, and deception follow through several layers, each one designed to look routine.
That creates a difficult problem for defenders. Security teams often focus on the first visible event, such as the suspicious message or the unusual attachment. RedFlick spreads the risk across the entire chain. A message filter may miss the email. An employee may open the decoy document. An endpoint tool may then need to recognize a hidden command, a mounted virtual disk, an unusual installer, and new scheduled tasks.
This illustrates the challenges for the CISO in the age of AI. Modern business moves quickly, and security teams cannot inspect every file by hand. Yet speed can turn convenience into exposure. A virtual disk attachment may support legitimate work. An installer may carry approved software. A scheduled task may serve a real maintenance function. Context matters, and context often arrives late.
The sensible response does not involve telling employees to fear every invitation or attachment. Organizations should block unnecessary virtual disk formats in email, inspect archive contents, monitor unusual LNK and MSI activity, and review new scheduled tasks against known software behavior. They should also train people to treat a second message containing a password protected archive as a warning sign, especially when the first message created urgency or curiosity.
RedFlick also deserves careful scrutiny in public reporting.
Calling it a “new technique” can make the threat sound more novel than it really is. The underlying ingredients remain familiar. The innovation lies in how Star Blizzard combines them, automates the sequence, and lowers the number of decisions a victim must make.
That distinction helps companies spend their effort wisely. They do not need a dramatic new security product simply because attackers gave an old method a new name. They need better visibility across ordinary system behavior, stronger controls around deceptive file types, and a willingness to question software that looks legitimate only because it follows a familiar pattern.
RedFlick shows how modern malware succeeds through choreography rather than spectacle. A believable message opens the door, a disguised file distracts the user, and routine Windows functions help CosmicPulse settle in quietly. The technique works because each step looks almost normal, and that is exactly why defenders must examine the whole sequence.
Digital Security: A Necessity for Modern Enterprises
The landscape of cybersecurity is constantly evolving, making it essential for businesses to stay informed and agile. Learning from both the successes and the missteps of leading companies in this field can provide valuable insights into effective risk management and threat mitigation strategies.
Key lessons to take away from this topic:
- Harden initial access. Enforce phishing-resistant MFA, patch internet-facing systems, disable unused services, and restrict macro/script execution.
- Detect anomalous execution. Deploy EDR with behavioral rules for unusual PowerShell, script interpreters, persistence mechanisms, and outbound connections—not merely known malware signatures.
- Limit blast radius. Apply least privilege, isolate critical networks, segment administrative accounts, and block unnecessary east-west traffic.
- Strengthen intelligence and response. Track RedFlick indicators through trusted threat-intelligence channels. Predefine containment, eradication, notification, and recovery procedures.
- Protect recovery pathways. Maintain offline, immutable backups. Test restoration regularly. Assume attackers may target identity systems, backups, and security tools.
Connection to the stated works: access hardening and monitoring reflect Securing Success in a Digitally Driven World; intelligence-led detection and response reflect Navigating Cyber Threats for Sustainable Growth; segmentation, tested backups, and recovery discipline reflect Building Resilience in the Age of Digital Transformation.
From the Author
The rising tide of cyber threats poses a significant challenge to organizations worldwide. Addressing this compounding problem requires a proactive stance, where continuous learning and collaboration are key to developing effective cybersecurity strategies.
I endeavor to curate stories like this one on my website. This serves a dual purpose: firstly, to provide a valuable reference for my writing endeavors, and secondly, to share insightful narratives with the wider community. If you like this story, you should check out some of the other stories in the Management section or Small Business section.
You can also find more of my Cybersecurity writings here in the Cybersecurity section.
To check the original story Click here
Expand Your Horizons
Here are some free Information Security Tools TrendMicro Tools.






