top of page

Hunt Star Blizzard RedFlick: the tasks that fetched CosmicPulse

Writer: Inception Security
Inception Security
23 hours ago
9 min read

Open Task Scheduler on the machine and three entries look like housekeeping: Internet Quality Test Connection, Network Configuration Manager, System Health Monitor. Microsoft Threat Intelligence reports that in April 2026 a Star Blizzard MSI installer created exactly those three, each with its own job, and that in at least one incident the first or third task deployed the CosmicPulse backdoor.


Microsoft Threat Intelligence published the research on 29 September 2026 and calls the delivery technique RedFlick. More than 100 organisations have been affected so far, mostly in the United States and the United Kingdom.


Three practical questions to carry through it. Can you name the owner of every scheduled task on your endpoints? Would you see conhost.exe starting curl, or control.exe loading from a network path? If a user opened a password-protected archive from an email this week, could you tell?


How the attack works


One user interaction, then ordinary Windows tools


Microsoft says Star Blizzard opens with an email that carries no attachment at all, which is what gets it past the filters and past the user. Only if the recipient replies does a follow-up arrive with a password-protected RAR or ZIP, and the password is supplied as an image in that email so no scanner can read it. The interaction itself is the delivery mechanism.


In mid-January 2026, the archive held a VHDX virtual disk, and inside it sat an LNK file disguised as a PDF, a hidden folder with a BAT script, and a legitimate decoy PDF to open. Opening the LNK started conhost.exe in a hidden window, cmd.exe ran the BAT, and the script opened the decoy while quietly invoking ssh.exe with PermitLocalCommand enabled and LocalCommand set to cmd.exe, which is how it retrieved the MSI. Every binary in that sentence ships with Windows.


The MSI created a scheduled task that uses control.exe to pull a CosmicPulse downloader, compiled as a Control Panel applet (CPL) DLL. The downloader is also known as NOROBOT or BAITSWITCH. It writes an encrypted AES key to HKCU\Software\Classes\.mollis, and a Python 3.8 bootstrapper decodes the CosmicPulse payload, also known as YESROBOT. RedFlick needs one user interaction, where the earlier ClickFix chains needed several.


April: three tasks with three jobs


By April the MSI installed three tasks posing as network components. "Internet Quality Test Connection" sends a UTF-16 and Base64-encoded string with the computer name and username to the C2 server, and can run a remote DLL through Control_RunDLL, reached by a WebDAV UNC path so the fetch travels over HTTP. "Network Configuration Manager" prepares the WebDAV client functionality the others rely on. "System Health Monitor" uses control.exe to reach a remote path on the hardcoded C2 server and run the next stage.


July: a PDF that carries the next step


In July the LNK used conhost.exe and curl to download a PDF from an actor-controlled server. PowerShell then searched the PDF for the magic header cAB, took the next 208 bytes of Base64 data, and ran the decoded command, which tried to download another MSI. Microsoft says the installer's PowerShell again tries to create two tasks, a helper and one that fetches a CPL applet.


A task name is a claim, not authority


A normal scheduled task has an owner you can name, a name that matches its product, and an action that runs a known binary. These tasks fail that test. The names claim network diagnostics, but the actions send host and user details outward and use control.exe to run code fetched over WebDAV. A name is an identity anyone can write. The action shows the authority the task exercises.


Risk: what the tasks hold


Microsoft has seen this activity affect over 100 organizations, primarily in the United States and United Kingdom, across at least 13 large-scale campaigns since January 2026. It names Ukrainian individuals and institutions, international NGOs, think tanks, governments, and financial institutions that have supported Ukraine as targets, and calls the activity cyberespionage. CISA attributes Star Blizzard to FSB Centre 18.


For a company, a persistent task is a standing foothold on a user's machine, renewed on a schedule nobody reviews. So if your organisation works anywhere near Ukraine policy, treat a match as an access question before it is a malware question: what could that user reach, and whose mail and documents do they handle?


Mitigate and reduce risk


Microsoft's own guidance, applied to this case:


  • Use phishing-resistant authentication and Conditional Access, and turn on Safe Links and Safe Attachments.

  • Turn on zero-hour auto purge so delivered mail is pulled back on new intelligence.

  • Run EDR in block mode, enable network protection, and use the attack surface reduction rules Microsoft lists for unprevalent executables and obfuscated scripts.

  • Restrict outbound SSH to external networks where it is not essential for business.


General-knowledge controls, all test first:


  • Quarantine or inspect inbound mail that pairs a password-protected archive with an image in the message body.

  • Block or alert on mounting VHDX files that originated from mail or downloads.

  • Block outbound WebDAV and SMB to the internet, and alert on control.exe loading from a network path.

  • Alert on ssh.exe run with LocalCommand options from user contexts.

  • Alert on scheduled task creation (Windows event 4698 is a common source) and keep Mark of the Web intact on archives and their contents.


How to hunt the activity


Hunts 1 to 3 start from Microsoft's Defender queries. Hunt 4 uses only the indicators in Microsoft's table. Microsoft warns its queries may surface benign activity, so read matches as leads. The table under the hunts, "Interpret before you escalate", says what is benign and what is not.


Hunt 1: conhost.exe launching curl


Microsoft's own Defender query comes first, covering the July technique, followed by Kibana, Splunk and Falcon translations.


Microsoft KQL (Defender)


DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName == "conhost.exe"
| where ProcessCommandLine has "curl"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessCommandLine, InitiatingProcessFileName, DeviceId, ProcessId, ProcessUniqueId, InitiatingProcessUniqueId

Kibana


process.name: "conhost.exe" AND process.command_line: *curl*

Splunk


index=YOUR_ENDPOINT_INDEX
| eval img=coalesce(Image, process_name, New_Process_Name), cmd=coalesce(CommandLine, Process_Command_Line, process)
| where match(img, "(?i)conhost\.exe$") AND like(lower(cmd), "%curl%")
| table _time host user img cmd ParentImage

Falcon CQL


#event_simpleName=ProcessRollup2
| FileName=/^conhost\.exe$/i
| CommandLine=/curl/i
| table([@timestamp, ComputerName, UserSid, ParentBaseFileName, FileName, CommandLine], limit=1000)

Field mapping: the KQL is Microsoft's. Kibana, Splunk, and Falcon fields are general knowledge (test first).


False positives: admins and scripts use curl, but conhost.exe launching it is unusual. Check the parent and destination.


Empty result: confirm command-line telemetry covers the window. Empty can mean no data.


Hunt 2: ssh.exe with PermitLocalCommand enabled


Microsoft's Defender query comes first, covering the January technique, followed by Falcon, Splunk and Kibana translations.


Microsoft KQL (Defender)


DeviceProcessEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has "ssh.exe"
| where ProcessCommandLine has "PermitLocalCommand=yes"
| where ProcessCommandLine has "LocalCommand=cmd.exe"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessCommandLine, InitiatingProcessParentFileName, DeviceId, ProcessId, InitiatingProcessId, ReportId

Falcon CQL


#event_simpleName=ProcessRollup2
| FileName=/^ssh\.exe$/i
| CommandLine=/PermitLocalCommand=yes/i
| CommandLine=/LocalCommand=cmd\.exe/i
| table([@timestamp, ComputerName, UserSid, ParentBaseFileName, FileName, CommandLine], limit=1000)

Splunk


index=YOUR_ENDPOINT_INDEX
| eval cmd=coalesce(CommandLine, Process_Command_Line, process)
| where like(lower(cmd), "%ssh.exe%") AND like(lower(cmd), "%permitlocalcommand=yes%") AND like(lower(cmd), "%localcommand=cmd.exe%")
| table _time host user ParentImage cmd

Kibana


process.command_line: *ssh.exe* AND process.command_line: *PermitLocalCommand=yes* AND process.command_line: *LocalCommand=cmd.exe*

Field mapping: Falcon, Splunk, and Kibana fields are general knowledge (test first).


False positives: developers using ssh local hooks. Escalate when the parent is a script or shortcut, not a terminal.


Empty result: check endpoints with ssh.exe send process events for the whole period.


Hunt 3: the three scheduled task names


Microsoft's persistence query searches process, device, and registry tables, followed by Splunk, Falcon, and Kibana versions.


Microsoft KQL (Defender)


union isfuzzy=true
(
DeviceProcessEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor") or AdditionalFields has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor")
| project Timestamp, DeviceName, ActionType, ProcessCommandLine, AdditionalFields
, RegistryKey = tostring(dynamic(null)), RegistryValueName = tostring(dynamic(null))
, SourceTable = "DeviceProcessEvents"
, ProcessId, AccountName, AccountDomain, AccountSid
)
,
(
DeviceEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor") or AdditionalFields has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor") or RegistryKey has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor") or RegistryValueName has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor")
| project Timestamp, DeviceName, ActionType, ProcessCommandLine, AdditionalFields, RegistryKey, RegistryValueName
, SourceTable = "DeviceEvents"
, ProcessId = long(null), AccountName = "", AccountDomain = "", AccountSid = ""
)
,
(
DeviceRegistryEvents
| where Timestamp > ago(7d)
| where RegistryKey has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor") or RegistryValueName has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor") or RegistryValueData has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor") or InitiatingProcessCommandLine has_any ("Internet Quality Test Connection","Network Configuration Manager","System Health Monitor")
| project Timestamp, DeviceName, ActionType
, ProcessCommandLine = InitiatingProcessCommandLine, AdditionalFields = ""
, RegistryKey, RegistryValueName
, SourceTable = "DeviceRegistryEvents"
, ProcessId = long(null), AccountName = "", AccountDomain = "", AccountSid = ""
)

Splunk


index=YOUR_ENDPOINT_INDEX ("Internet Quality Test Connection" OR "Network Configuration Manager" OR "System Health Monitor")
| eval task=coalesce(Task_Name, TaskName, registry_key_name, object_name)
| eval cmd=coalesce(CommandLine, Process_Command_Line, process)
| table _time host EventCode user task cmd
| sort 0 _time

Falcon CQL


#event_simpleName=ProcessRollup2
| CommandLine=/Internet Quality Test Connection|Network Configuration Manager|System Health Monitor/i
| table([@timestamp, ComputerName, UserSid, FileName, CommandLine], limit=1000)

Kibana


process.command_line: (*Internet*Quality*Test*Connection* or *Network*Configuration*Manager* or *System*Health*Monitor*)

Field mapping: use an index holding Windows Security, Sysmon, or task logs. The Splunk, Falcon, and Kibana field names are general knowledge (test first). Falcon and Kibana see command lines only, so add task or registry telemetry.


False positives: a vendor could reuse a generic name. Read the action, not the name.


Empty result: task creation auditing is often off, so empty can reflect missing logs.


Hunt 4: indicator sweep from Microsoft's published IoCs


Microsoft's ASIM sweep of the domains and IPs from its indicator table, then Kibana, Splunk, and Falcon versions.


Microsoft KQL (Sentinel ASIM)


let lookback = 30d;
let ioc_ip_addr = dynamic(["103.245.231.248", "2.57.241.246", "89.125.209.168", "103.245.231.79", "45.84.59.66", "103.160.59.97"]);
let ioc_domains = dynamic(["etia.ca", "groy.cc", "gliderrompercycl.com", "muvb.net", "divekickspolic.org", "matjk.click", "bpdaersa.click", "stuseamandesilt.org", "Itechx.tel", "guach.net", "ruten.observer", "byveo.org", "secure-dns-hub.com", "qumel.link", "cyrna.top", "drasw.club"]);
_Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now())
| where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains)
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), EventCount=count()
    by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor

Kibana


destination.ip: ("103.245.231.248" or "2.57.241.246" or "89.125.209.168" or "103.245.231.79" or "45.84.59.66" or "103.160.59.97")
or destination.domain: ("etia.ca" or "groy.cc" or "gliderrompercycl.com" or "muvb.net" or "divekickspolic.org" or "matjk.click" or "bpdaersa.click" or "stuseamandesilt.org" or "Itechx.tel" or "guach.net" or "ruten.observer" or "byveo.org" or "secure-dns-hub.com" or "qumel.link" or "cyrna.top" or "drasw.club")
or dns.question.name: ("etia.ca" or "groy.cc" or "gliderrompercycl.com" or "muvb.net" or "divekickspolic.org" or "matjk.click" or "bpdaersa.click" or "stuseamandesilt.org" or "Itechx.tel" or "guach.net" or "ruten.observer" or "byveo.org" or "secure-dns-hub.com" or "qumel.link" or "cyrna.top" or "drasw.club")

Splunk


index=YOUR_NETWORK_INDEX
    (dest_ip IN ("103.245.231.248","2.57.241.246","89.125.209.168","103.245.231.79","45.84.59.66","103.160.59.97")
    OR dest IN ("etia.ca","groy.cc","gliderrompercycl.com","muvb.net","divekickspolic.org","matjk.click","bpdaersa.click","stuseamandesilt.org","Itechx.tel","guach.net","ruten.observer","byveo.org","secure-dns-hub.com","qumel.link","cyrna.top","drasw.club"))
| stats earliest(_time) AS first latest(_time) AS last count BY src dest dest_ip

Falcon CQL


#event_simpleName=/^(DnsRequest|NetworkConnectIP4)$/
| in(field=[DomainName, RemoteAddressIP4], values=["103.245.231.248","2.57.241.246","89.125.209.168","103.245.231.79","45.84.59.66","103.160.59.97","etia.ca","groy.cc","gliderrompercycl.com","muvb.net","divekickspolic.org","matjk.click","bpdaersa.click","stuseamandesilt.org","Itechx.tel","guach.net","ruten.observer","byveo.org","secure-dns-hub.com","qumel.link","cyrna.top","drasw.club"], ignoreCase=true)
| table([@timestamp, ComputerName, DomainName, RemoteAddressIP4, ContextBaseFileName], limit=1000)

Field mapping: ECS, Splunk, and Falcon fields are general knowledge (test first). Microsoft defangs indicators with brackets, so these use plain form. Microsoft writes Itechx.tel with a capital I, and some fields are case-sensitive.


False positives: shared hosting can add noise. Confirm which process made the connection.


Empty result: infrastructure changes, so empty does not clear a host. DNS or proxy logs must cover the period.


Interpret before you escalate


Finding

Benign read

Escalate when

conhost.exe launching curl

An admin script or dev tool

The parent is an LNK or script, and curl fetches a PDF from an unfamiliar host

ssh.exe with PermitLocalCommand=yes and LocalCommand=cmd.exe

A developer or admin test

It runs from a user profile or a mounted disk, or follows an archive being opened

One of the three task names

A vendor reusing a generic name

The action calls control.exe, a UNC path, or a WebDAV target

A hit on Microsoft's domains or IPs

Noisy shared hosting

The connection came from control.exe, msiexec.exe, conhost.exe, or PowerShell

Empty results

Nothing matched

Log coverage or auditing gaps mean you cannot tell, so fix those first


Sources



What This Means for Your Team


Start with the list of scheduled tasks and ask who owns each name, because a name that sounds like maintenance is not evidence of maintenance. If your people work anywhere near Ukraine policy, run the four hunts and then go check the mail for follow-ups carrying archive attachments with passwords supplied as images. A match is a prompt to look at the user and the mailbox, not only the machine. And if the hunts come back empty, be honest about which of those four you could actually have answered, because command-line telemetry is the usual gap: Defender is deployed but the process command line was never retained, scheduled task creation events go nowhere, and nobody has ever looked at Task Scheduler on an endpoint that was not already suspected. Empty searches on telemetry you never collected are not clearance, and the difference between those two statements is the whole job.


Inception Protection


Inception Protection is our managed detection and response service, and it works with the Microsoft licenses you already have. For a case like this, we read the archive email, the endpoint process chain, and the scheduled task together, as one story. You keep ownership, and we help watch what follows.


Inception Foresight


If you want to see how well your Microsoft environment would surface activity like this, the free Inception Foresight M365 Assessment is a good place to start: https://www.inceptionsecurity.com/m365assessment. You can also follow Inception Security on LinkedIn and @inceptionsec on X.

bg-map-white.png

INCEPTION SECURITY™

A cybersecurity company with in depth knowledge of the threat landscape and security controls.

NAVIGATION

GET IN TOUCH

© 2025 All Rights Reserved by INCEPTION SECURITY™ .

bottom of page