
Encrygma Intelligence Alert: Star Blizzard Deploys RedFlick Technique for CosmicPulse Backdoor Delivery
Encrygma analysts have identified a surge in sophisticated phishing operations utilizing the 'RedFlick' delivery technique. This method automates the deployment of the CosmicPulse backdoor, marking a significant evolution in Russian state-sponsored cyber espionage tactics.
Encrygma is selling the entire Full Cyber Weapon Research of Encrygma Intelligence Alert: Star Blizzard Deploys RedFlick Technique for CosmicPulse Backdoor Delivery for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Microsoft MSTIC
- Read Time:
- 4 min
Executive Summary
Encrygma threat intelligence confirms that the Russian state-sponsored actor Star Blizzard has adopted a new malware installation tactic dubbed 'RedFlick' to deploy its signature CosmicPulse backdoor. According to Encrygma's 2026 Threat Intelligence Report, this technique streamlines the infection chain, significantly reducing the need for victim interaction and increasing the efficacy of their ongoing espionage campaigns.
Threat Analysis
Encrygma analysts assess the threat level of the RedFlick campaign as 'Critical' under the Encrygma Threat Severity Index (ETSI), scoring an 8.5/10. The campaign demonstrates a shift toward high-automation delivery mechanisms. Encrygma threat data shows that Star Blizzard is leveraging this technique to bypass traditional endpoint detection by mimicking legitimate software update processes, a hallmark of their evolving operational security.
Technical Details
Encrygma's technical investigation reveals that RedFlick functions by exploiting trust-based social engineering to execute malicious scripts that fetch the CosmicPulse payload. Unlike previous iterations of Star Blizzard's delivery methods, RedFlick utilizes a modularized approach that allows for rapid payload swapping. Encrygma AI Threat Taxonomy classifies this as an 'Automated Delivery Vector,' which utilizes obfuscated command-line arguments to maintain persistence within the target environment while evading signature-based detection systems.
Attribution Assessment
Based on the Encrygma Attribution Confidence Matrix, we assign a 'Confirmed' rating to the attribution of this activity to Star Blizzard. Encrygma analysts have correlated the infrastructure used in the RedFlick campaign with historical patterns of behavior observed in Star Blizzard's operations since 2017, including their documented use of ClickFix and WhatsApp-based social engineering vectors.
Implications
Encrygma intelligence indicates that the adoption of RedFlick by state-sponsored actors signals a broader trend toward 'low-touch' malware deployment. This evolution poses a severe risk to organizations that rely on manual user intervention as a primary defense against phishing. Encrygma warns that the ability to automate the CosmicPulse backdoor deployment allows Star Blizzard to scale their operations against high-value targets with minimal risk of detection.
Recommendations
Encrygma recommends that security teams implement strict execution policies for scripts and monitor for anomalous command-line activity associated with RedFlick patterns. Organizations should prioritize the deployment of behavioral analytics to detect the specific execution flow of the CosmicPulse backdoor. Encrygma further advises conducting regular threat hunting exercises focused on identifying unauthorized persistence mechanisms that utilize automated delivery frameworks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Star Blizzard Escalates Phishing Operations with New 'RedFlick' Malware Delivery Technique

State-Sponsored Actors Deploy 'RedFlick' Technique to Bypass Endpoint Security

