Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hackers Launch New Phishing Campaign Targeting 100+ Organizations

Russian Hackers Launch New Phishing Campaign Targeting 100+ Organizations

Posted on September 30, 2026 By CWS

Russian hackers, linked to state operations, have broadened a phishing campaign that employs a novel technique known as the RedFlick delivery chain, impacting over 100 organizations. The operation involves deceptive emails that mimic normal professional exchanges, aiming to catch recipients off guard.

Expanding Phishing Techniques

In a shift from traditional methods, the hackers have forgone the typical malicious attachments for emails that appear as standard communications. This strategy was implemented in at least 13 campaigns from January to August 2026, primarily affecting entities in the United States and the United Kingdom.

Key targets of this campaign include government bodies, diplomatic circles, research institutions, public policy groups, journalists, and financial organizations, especially those with connections to Ukraine-related activities.

Strategic Changes by Star Blizzard

Analysts from Field Effect have observed that the group, known as Star Blizzard, ColdRiver, or Callisto, has transitioned from focused spear-phishing to broader initial contact strategies. This approach allows them to identify potential responders before deploying harmful files.

Field Effect’s report, shared with Cyber Security News, highlighted the use of compromised websites to create accounts for sending phishing emails, continuing a trend of evolving tactics, including previous QR-code attacks through WhatsApp.

Phishing Execution and Countermeasures

The initial email lacks any direct threats, instead attempting to engage the recipient in dialogue, exploiting normal business interactions. A response from the recipient indicates trust, leading to the delivery of a password-protected RAR or ZIP file, with the password provided as an image within the email.

Security measures are circumvented as the email content appears benign. Once the archive is accessed, it can contain harmful components such as a VHDX virtual disk or an LNK file disguised as a PDF. These files execute scripts to download additional malware from attacker-controlled servers.

Recent developments include integrating a password-protected RAR within a ZIP file, further obscuring the attack. PowerShell scripts are then used to execute the malicious code, complicating detection efforts.

Detecting and Mitigating Threats

Microsoft has tracked RedFlick’s communication with external infrastructure, highlighting the creation of scheduled tasks and deployment of the CosmicPulse backdoor as key indicators of compromise.

Organizations are advised to scrutinize encrypted archives arriving after initial attachment-free emails, especially where passwords are shared within the conversation. Security teams should correlate archive actions with VHDX and LNK activity, as well as unexpected external connections.

Upon suspicion of execution, devices should be isolated, and the email trail preserved for analysis. Reviewing user accounts and recent communications may reveal broader targeting, underscoring the importance of verifying unexpected requests through established channels, especially for Ukraine-related engagements.

Cyber Security News Tags:Callisto, COLDRIVER, CosmicPulse, cyber attack, cyber threat, Cybersecurity, email security, Field Effect, Malware, Microsoft, Phishing, RedFlick, Russian hackers, Star Blizzard, Ukraine

Post navigation

Previous Post: Citrix Vulnerabilities Exploited by Hackers, Warns Google

Related Posts

AsyncRAT Exploits Remote Tools for Hidden Access AsyncRAT Exploits Remote Tools for Hidden Access Cyber Security News
Elite Cyber Veterans Launch Blast Security with M to Turn Cloud Detection into Prevention Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention Cyber Security News
Weaponized Chrome Extension Affects 1.7 Million Users Despite Google’s Verified Badges Weaponized Chrome Extension Affects 1.7 Million Users Despite Google’s Verified Badges Cyber Security News
Evooo1Bot Botnet Exploits Edge Devices with DDoS Attacks Evooo1Bot Botnet Exploits Edge Devices with DDoS Attacks Cyber Security News
Odido Telecom Hacked: 6.2 Million Accounts Compromised Odido Telecom Hacked: 6.2 Million Accounts Compromised Cyber Security News
Chollima Hackers Exploit PHP Developers via Packagist Chollima Hackers Exploit PHP Developers via Packagist Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Hackers Launch New Phishing Campaign Targeting 100+ Organizations
  • Citrix Vulnerabilities Exploited by Hackers, Warns Google
  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Hackers Launch New Phishing Campaign Targeting 100+ Organizations
  • Citrix Vulnerabilities Exploited by Hackers, Warns Google
  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark