Russian State Actor Star Blizzard deploys CosmicPulse backdoor via new RedFlick technique
BleepingComputer reports on novel malware installation method targeting targeted campaigns

Key Takeaways
- Star Blizzard, a Russian state actor, has been observed using a new malware installation tactic dubbed "RedFlick".
- The RedFlick technique is used to deploy the CosmicPulse backdoor.
- The activity was reported by BleepingComputer on 2026-09-30.
- Specific technical details of the RedFlick method, target geography, and scope of campaigns are unverified.
- No patches or vendor advisories were mentioned in the source material.
Quick answers
- What happened?
- According to BleepingComputer, the Russian state actor Star Blizzard has been observed using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. The report indicates this technique was used in targeted campaigns, though specific exploitation details, target geography, and the scope of affected systems remain unverified. No patch or mitigation guidance specific to RedFlick was provided in the source material.
- What should defenders do?
- The source does not provide specific mitigation steps for RedFlick. General guidance includes maintaining standard security hygiene, monitoring for Star Blizzard indicators of compromise, and applying the principle of least privilege. Organizations should review security posture and ensure endpoint detection capabilities are tuned for state-actor tooling.
BleepingComputer reports that the Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. The report, published on 2026-09-30, notes that RedFlick was used in targeted campaigns; however, the source snippet does not provide technical details of the RedFlick mechanism, the specific sectors or geographies targeted, or the full extent of the campaigns. The CosmicPulse backdoor is a known tool associated with Star Blizzard, but the article does not describe the delivery vector, privilege escalation methods, or command-and-control infrastructure beyond the deployment tactic. No vendor advisories, CVEs, or patches were mentioned in connection with the RedFlick technique. Mitigation is described as likely involving standard security hygiene and monitoring for Star Blizzard indicators, though the source does not specify concrete indicators of compromise.
Security Details
The RedFlick technique represents a new malware installation method attributed to Star Blizzard for deploying the CosmicPulse backdoor. Technical details of the RedFlick mechanism, exploitation vectors, and specific targets are not provided in the reporting source and remain unverified. The CosmicPulse backdoor is associated with Star Blizzard's targeted campaigns.
Mitigation
The source does not provide specific mitigation steps for RedFlick. General guidance includes maintaining standard security hygiene, monitoring for Star Blizzard indicators of compromise, and applying the principle of least privilege. Organizations should review security posture and ensure endpoint detection capabilities are tuned for state-actor tooling.
Sources
BleepingComputer
Russian state hackers use new RedFlick technique to push malware
Sep 30, 2026 · 20:34
Original link
Related Security News

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver Remote Access Trojans (RATs). Huntress observed the activity in late September 2026, marking another instance of abuse in trusted artificial intelligence platforms. The campaign directs victims from AI-generated content to external sites using ClickFix social engineering lures that trick users into executing commands that deliver malware.




