Russian state hackers use new RedFlick technique to push malware

Executive Summary

Russian state-sponsored actor Star Blizzard has deployed its CosmicPulse backdoor using a new installation technique called RedFlick. The method allows the malware to be delivered and installed on target systems with minimal detection, expanding the actor’s ability to establish persistent footholds. The technique represents a new evolution in the actor’s toolset for delivering backdoor capabilities.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-30T20:34:01+00:00 - Category: threat-intel

Original Description: The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]

"Learn wisdom from the ways of a seedling. A seedling which is never hardened off through stressful situations will never become a strong productive plant."

— Stephen Sigmund
Source: Bleeping Computer