CosmicPulse is a Python-based backdoor used by Star Blizzard, a Russian state-linked threat actor associated with Centre 18 of Russia’s Federal Security Service. Also known as YESROBOT, the backdoor provides persistent access to compromised Windows endpoints. Its associated downloader, known as NOROBOT or BAITSWITCH, masquerades as a Windows Control Panel applet and retrieves separate archives containing a Python runtime and bootstrapper, and the backdoor payload. The installation process uses an AES key stored in the Windows Registry to decode the payload.
CosmicPulse is deployed through Star Blizzard’s RedFlick delivery chain, which uses scheduled tasks to install the backdoor and support persistence. Infection commonly begins with attachment-free phishing correspondence, followed by a password-protected archive after the recipient responds. Archives contain virtual disk images or Windows shortcuts disguised as PDF documents. Opening a malicious file initiates scripts and legitimate Windows utilities that retrieve installers and subsequent payloads. Variants use WebDAV, concealed PowerShell commands in PDF documents, and scheduled tasks masquerading as network or system-maintenance components. Earlier delivery chains used ClickFix social engineering. These mechanisms conceal malicious activity and reduce the interaction needed to initiate installation.
Associated campaigns have targeted Ukrainian individuals and institutions and Ukraine-related government, diplomatic, NGO, think-tank, research, media, and financial organizations, particularly in the United States and United Kingdom.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft observed RedFlick communicating with remote infrastructure, creating scheduled tasks, and deploying CosmicPulse in at least one incident, providing persistent access to the affected Windows endpoint.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon opening a file within the archive, RedFlick uses scheduled tasks to install the CosmicPulse backdoor.
L’installeur MSI crée trois tâches planifiées masquées en composants réseau légitimes.
Star Blizzard sends a second message containing a password-protected RAR or ZIP archive that triggers the malware delivery.
The follow-up message carries a password-protected RAR or ZIP archive, while its password appears as an image in the email... In July, the operators added another layer by placing a password-protected RAR archive inside a ZIP file.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed by Star Blizzard through phishing campaigns using password-protected archives, VHDX images, disguised LNK files, and MSI installers. NOROBOT and BAITSWITCH identify the downloader stage; YESROBOT identifies the backdoor payload. The RedFlick delivery technique uses scheduled tasks to support deployment and persistence while reducing required victim interaction. Described tasks can transmit encoded device information to command-and-control infrastructure, invoke attacker-controlled DLLs, support WebDAV-based execution, and retrieve and execute the downloader.
A backdoor installed by the RedFlick delivery mechanism in Star Blizzard phishing campaigns.
Downloader and backdoor payload used in the RedFlick infection chain. It is executed as a Control Panel DLL via control.exe, downloads Python/bootstrapper and payload archives, and uses an AES key stored in the .mollis user registry key.
A backdoor deployed by the RedFlick delivery chain, providing persistent access to compromised Windows devices after phishing-based execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.