<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cosmicpulse - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cosmicpulse/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 19:17:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cosmicpulse/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Star Blizzard Evolution and RedFlick Malware Delivery Technique</title><link>https://feed.craftedsignal.io/briefs/2026-09-star-blizzard-redflick/</link><pubDate>Tue, 29 Sep 2026 19:17:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-star-blizzard-redflick/</guid><description>Russian state actor Star Blizzard has shifted to large-scale phishing campaigns and adopted the RedFlick delivery technique to deploy the CosmicPulse backdoor via scheduled tasks with minimal user interaction.</description><content:encoded><![CDATA[<p>Since January 2026, the Russian state-sponsored threat actor Star Blizzard (subordinate to FSB Centre 18) has evolved its operational tradecraft to include large-scale phishing campaigns and a novel malware delivery mechanism dubbed &quot;RedFlick.&quot; This pivot represents a significant departure from previous, more targeted spear-phishing operations, allowing the actor to scale operations significantly by utilizing automated mass-mailing platforms. The RedFlick technique streamlines the infection chain, requiring only a single user interaction to initiate the deployment of the custom CosmicPulse backdoor. These operations target individuals and institutions supporting Ukraine, including government officials, NGOs, think tanks, and international financial organizations, particularly within the United States and the United Kingdom. With over 100 organizations affected, this evolution indicates a persistent and adaptive threat capable of rapid TTP iteration in response to public disclosure and defensive hardening.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The actor conducts reconnaissance to identify targets associated with Ukraine, financial policy, or international relations.</li>
<li>Mass-phishing emails are distributed using accounts on compromised websites to bypass reputation filters, impersonating legitimate organizations or events (e.g., roundtable discussions).</li>
<li>The victim receives an email containing an attachment which, when opened, initiates the RedFlick infection flow.</li>
<li>RedFlick executes locally, reducing user friction by requiring only a single interaction compared to legacy ClickFix-based chains.</li>
<li>The infection process configures a scheduled task on the target system to achieve persistence.</li>
<li>The scheduled task executes a command to download and install the CosmicPulse backdoor from actor-controlled infrastructure.</li>
<li>The CosmicPulse backdoor enables remote access, providing the threat actor with persistent entry for cyberespionage objectives.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The evolution to RedFlick and large-scale phishing has enabled Star Blizzard to successfully compromise over 100 organizations across the United States and the United Kingdom. Victims include government officials, think tanks, NGOs, and financial institutions involved in international policy and support for Ukraine. Successful compromise allows the actor to perform persistent cyberespionage, potentially resulting in the exfiltration of sensitive diplomatic, strategic, and financial intelligence.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize hardening against phishing and malicious task creation by implementing the following:</p>
<ul>
<li>Deploy endpoint detection rules to monitor for suspicious scheduled task creation and execution chains.</li>
<li>Implement email filtering controls that block messages originating from known compromised infrastructure and investigate mass-mail patterns.</li>
<li>Audit scheduled tasks periodically for unauthorized or unusual commands, specifically looking for tasks spawned from common user document folders.</li>
<li>Review network egress logs for connections to unknown domains following the execution of suspicious user-space processes.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>phishing</category><category>espionage</category><category>redflick</category><category>cosmicpulse</category><category>star-blizzard</category><category>windows</category><category>macos</category></item></channel></rss>