Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Star Blizzard’s RedFlick Phishing Chain Targets More Than 100 Organizations
Star Blizzard’s RedFlick Phishing Chain Targets More Than 100 Organizations
Read Time:3 Minute, 16 Second

A Russia-linked threat group has expanded its phishing activity with a delivery chain called RedFlick, targeting more than 100 organizations while replacing obvious first-message payloads with ordinary-looking professional conversation. The operation was observed in at least 13 campaigns between January and August 2026, primarily affecting targets in the United States and United Kingdom.

Government, diplomatic, public-policy, research, journalism and financial organizations connected to Ukraine were prominent among the targets. Analysts associate the activity with Star Blizzard, a group also tracked as ColdRiver and Callisto. The campaign illustrates a shift from narrowly tailored spear-phishing toward broader initial-contact activity designed to identify people who are willing to engage.

The first email is intentionally clean

RedFlick begins without an attachment, exploit or malicious link. Operators pose as plausible contacts and start discussions about invitations, policy work, research collaboration, financial matters or document sharing. A response gives the attacker evidence that the address is active and that the recipient may accept a later file.

The follow-up then introduces a password-protected RAR or ZIP archive. The password may be embedded in an image within the email, an approach that can obstruct automated extraction and inspection. Because the attachment arrives during an established exchange, it can also feel more credible than an unsolicited file.

Inside the archive, victims may find a VHDX virtual disk or a Windows LNK shortcut disguised as a PDF. Opening it triggers scripts and legitimate Windows components that retrieve additional material from attacker-controlled infrastructure. Compromised websites have also been used to create or support accounts involved in sending the messages.

RedFlick leads to persistent access

From April onward, observed installers created scheduled tasks, collected basic host details, enabled WebDAV access and fetched components used to install the CosmicPulse backdoor. Scheduled tasks provide a dependable way to restart malicious code, while WebDAV offers a built-in channel for reaching remote files without introducing a custom protocol.

The operators added more layers in July. A ZIP file contained a second password-protected RAR archive, and its shortcut downloaded a PDF holding encoded data. PowerShell extracted and executed that data to retrieve an MSI installer. Each step separated the visible document from the final payload and made the sequence harder to understand from the email alone.

Microsoft observed RedFlick communicating with remote systems, creating scheduled tasks and deploying CosmicPulse in at least one incident. Once installed, the backdoor can preserve access to a Windows endpoint even after the original message and archive are no longer visible to the user.

What defenders should hunt for

Email teams should look beyond the attachment itself and reconstruct the whole conversation. An encrypted archive that follows a harmless first message—especially one that claims a file was previously forgotten—deserves additional scrutiny. Delivery should be distinguished from execution by identifying which recipients downloaded, extracted, mounted or opened the content.

  • Correlate encrypted RAR or ZIP delivery with VHDX mounting and LNK execution.
  • Review PowerShell, MSI installation and WebDAV activity following archive extraction.
  • Hunt for newly created scheduled tasks and unfamiliar outbound connections.
  • Preserve the full email thread and original attachments during incident response.
  • Inspect mailbox rules, active sessions and sent messages for signs of account misuse.

Trust develops across the thread

The campaign succeeds by exploiting human expectations rather than a software vulnerability. A clean opening message can pass technical controls and build social context before any dangerous content arrives. Organizations handling sensitive geopolitical work should encourage staff to verify unexpected collaboration requests through a known phone number or separate trusted channel.

Security awareness programs should also emphasize that password protection is not proof of confidentiality or legitimacy. In this campaign, encryption functions as an inspection barrier. Combining conversation-aware email analysis with endpoint telemetry offers the best chance of catching the transition from a seemingly normal exchange to persistent compromise.

Source: Cyber Security News, drawing on findings attributed to Field Effect and Microsoft.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Star Blizzard’s RedFlick Phishing Chain Targets More Than 100 Organizations, use the discussion on Forum.

>> forum community

Comments

Leave a Reply