The PDF in the password-protected zip was not a PDF
For most of this year the fashionable way to get malware onto a Windows PC has been to ask the victim to do it: copy this line, press Windows+R, paste, enter. Star Blizzard, a Russian state group Microsoft has tracked for years, has gone the other way. Its new chain, written up by Microsoft on 29 September under the name RedFlick, needs one double-click.
It starts politely. An email that looks like an invitation, a reply from you, and only then the attachment: a password-protected ZIP or RAR, with the password sent as an image so scanners cannot read it. Inside is a VHDX file, a virtual hard disk. Windows mounts those with a double-click and shows them as a new drive, and on that drive sits a file wearing a PDF icon. It is a shortcut. Opening it quietly runs a command while a real decoy PDF opens on screen, so nothing looks wrong. From there an MSI installer goes in, three scheduled tasks are created to split the work up and stay out of sight, and the end of the line is a backdoor called CosmicPulse.
Microsoft counted at least 13 large-scale campaigns since January hitting more than 100 organisations, mostly in the US and UK, aimed at NGOs, think tanks, journalists and people connected to support for Ukraine. You are almost certainly not a target. The technique is the point, because these things filter down to ordinary criminals within months, and it has no obvious tell.
Two habits are worth the effort. Turn on file extensions in File Explorer, under View then Show, so a shortcut pretending to be a PDF reads as .lnk. And treat a password-protected archive from an email as a warning, not a courtesy: the password exists to get the file past the scanner. If something did run, Tendvane's safety check goes through scheduled tasks and startup entries, which is exactly where a chain like this parks itself.