RedFlick Phishing Attack Hits Over 100 Orgs With Sophisticated Chain

Russian state-linked hacking group Star Blizzard—also called ColdRiver or Callisto—has rolled out a new phishing campaign dubbed RedFlick that has struck more than 100 organizations so far in 2026. The wave spans at least 13 operations from January through August, primarily affecting targets in the United States and United Kingdom. Targets include groups involved in diplomacy, research, policy, journalism, finance—especially those with Ukraine ties.

How RedFlick Moves

Instead of leading with an overtly malicious email attachment, RedFlick begins with a benign-looking message—no malware, no exploit—designed to mimic professional correspondence. The attackers aim to engage recipients first: once someone replies, they send a second email containing a password-protected RAR or ZIP file, with the password presented as an image embedded in the conversation.

Inside that archive, the contents are carefully disguised. Attackers commonly hide a Windows shortcut (LNK) or a virtual disk (VHDX), camouflaged as a PDF. These items trigger scripts and legitimate system tools to fetch further payloads from attacker-controlled servers. In later variants, a password-protected RAR is embedded inside a ZIP; its shortcut leads to a PDF with encoded content that PowerShell extracts and runs to launch an MSI installer—separating the visible document from actual malicious activity.

Persistence & Tactical Moves

Once inside a system, RedFlick implants several mechanisms to remain persistent. Operators establish scheduled tasks on Windows, collect system metadata, enable WebDAV access (which allows remote file sharing), and deploy a backdoor named CosmicPulse.

These techniques—scheduled tasks, proprietary stealth via encrypted archives, LNK/VHDX misdirection, and hidden MSI installations—are designed to evade email scanning and threaten long-lived intrusion. In at least one incident, Microsoft has observed this full chain in action.

What Defenders Should Do Now

Security teams should be alert for unusual email patterns—especially those that start clean, then lead to password-protected attachments in follow-up messages. It’s important to watch for signs of archive extraction, VHDX or LNK execution, MSI installers, PowerShell usage, scheduled tasks, WebDAV traffic, or unexpected external connections.

If an attack is even suspected, isolating affected machines, preserving emails and archives, and examining persistence mechanisms and network logs are key. Investigating a user’s active sessions, mailbox rules, and any unfamiliar scripts or tasks also helps uncover deeper compromise.

This campaign underscores a shift: state-linked hackers are moving from narrow, highly targeted spear-phishing to broader initial-contact operations that allow filtering—identifying who’s likely to engage before dropping the payload.

What this means:RedFlick isn’t just another phishing tactic—it’s a refined model blending social engineering, technical obfuscation, and layered attack phases to bypass defenses. For organizations, especially those working on Ukraine-focused policy, diplomacy, journalism, research, or finance, even “safe” incoming emails deserve scrutiny. Forward-looking SOCs need to build detection not just around payloads, but conversation lifecycles and the lag between benign exchanges and malicious follow-ups.