Russian hackers, linked to state operations, have broadened a phishing campaign that employs a novel technique known as the RedFlick delivery chain, impacting over 100 organizations. The operation involves deceptive emails that mimic normal professional exchanges, aiming to catch recipients off guard.
Expanding Phishing Techniques
In a shift from traditional methods, the hackers have forgone the typical malicious attachments for emails that appear as standard communications. This strategy was implemented in at least 13 campaigns from January to August 2026, primarily affecting entities in the United States and the United Kingdom.
Key targets of this campaign include government bodies, diplomatic circles, research institutions, public policy groups, journalists, and financial organizations, especially those with connections to Ukraine-related activities.
Strategic Changes by Star Blizzard
Analysts from Field Effect have observed that the group, known as Star Blizzard, ColdRiver, or Callisto, has transitioned from focused spear-phishing to broader initial contact strategies. This approach allows them to identify potential responders before deploying harmful files.
Field Effect’s report, shared with Cyber Security News, highlighted the use of compromised websites to create accounts for sending phishing emails, continuing a trend of evolving tactics, including previous QR-code attacks through WhatsApp.
Phishing Execution and Countermeasures
The initial email lacks any direct threats, instead attempting to engage the recipient in dialogue, exploiting normal business interactions. A response from the recipient indicates trust, leading to the delivery of a password-protected RAR or ZIP file, with the password provided as an image within the email.
Security measures are circumvented as the email content appears benign. Once the archive is accessed, it can contain harmful components such as a VHDX virtual disk or an LNK file disguised as a PDF. These files execute scripts to download additional malware from attacker-controlled servers.
Recent developments include integrating a password-protected RAR within a ZIP file, further obscuring the attack. PowerShell scripts are then used to execute the malicious code, complicating detection efforts.
Detecting and Mitigating Threats
Microsoft has tracked RedFlick’s communication with external infrastructure, highlighting the creation of scheduled tasks and deployment of the CosmicPulse backdoor as key indicators of compromise.
Organizations are advised to scrutinize encrypted archives arriving after initial attachment-free emails, especially where passwords are shared within the conversation. Security teams should correlate archive actions with VHDX and LNK activity, as well as unexpected external connections.
Upon suspicion of execution, devices should be isolated, and the email trail preserved for analysis. Reviewing user accounts and recent communications may reveal broader targeting, underscoring the importance of verifying unexpected requests through established channels, especially for Ukraine-related engagements.
