Gbhackers iconGbhackersSep 30, 2026

RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor

Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked by Microsoft as RedFlick. Microsoft Threat Intelligence reported that the group, which CISA attributes to Russia's Federal Security Service (FSB) Center 18, conducted at least 13 phishing campaigns between January and August 2026.

RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor

Share this story

Send the public story page.

Useful takeaways from this story.

Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked by Microsoft as RedFlick.

Microsoft Threat Intelligence reported that the group, which CISA attributes to Russia's Federal Security Service (FSB) Center 18, conducted at least 13 phishing campaigns between January and August 2026.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked by Microsoft as RedFlick. Microsoft Threat Intelligence reported that the group, which CISA attributes to Russia's Federal Security Service (FSB) Center 18, conducted at least 13 phishing campaigns between January and August 2026.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app