Russian state-backed hackers from the group Star Blizzard have deployed a novel malware delivery method called RedFlick to install their CosmicPulse backdoor on target systems. The technique emerged in late September 2026 and was first observed in cyber espionage campaigns against government and diplomatic entities. Security researchers identified the activity during routine threat intelligence monitoring, noting its use in targeted phishing operations. RedFlick does not represent a fundamentally new cyberattack method but rather an innovative application of existing tactics to bypass detection. Attackers use legitimate Windows processes to execute malicious code in memory, avoiding traditional file-based defenses. This approach allows the CosmicPulse backdoor to establish persistence without leaving obvious traces on disk, making forensic analysis more difficult for defenders. How RedFlick Evades Traditional Defenses The technique leverages process injection and living-off-the-land binaries to blend malicious activity with normal system operations.
By hijacking trusted applications, Star Blizzard reduces the likelihood of triggering endpoint detection and response alerts. Researchers noted that the group specifically tailored RedFlick to target environments with strict application control policies, where conventional malware would fail. What Makes CosmicPulse Particularly Dangerous CosmicPulse provides attackers with extensive remote access capabilities, including file exfiltration, keylogging, and command execution. Its modular design allows operators to deploy additional payloads based on intelligence value. Previous versions of the backdoor have been linked to data theft from foreign ministries and NATO-affiliated organizations, suggesting a continued focus on geopolitical intelligence gathering. Frequently Asked Questions How does RedFlick differ from earlier malware delivery methods used by Star Blizzard? RedFlick focuses on stealthy in-memory execution using legitimate system tools, whereas prior techniques relied more heavily on malicious files or scripts that were easier to detect with traditional antivirus software.
Which sectors are most at risk from this new tactic? Government agencies, diplomatic institutions, and organizations involved in international policy or defense are primary targets, based on observed patterns in Star Blizzard’s past operations. Can existing security tools detect RedFlick activity? While challenging, advanced endpoint solutions that monitor process behavior and memory anomalies can identify signs of the technique, particularly when combined with network traffic analysis.