← Back to Daily Briefing (#CosmicPulse)

Star Blizzard Scales Phishing Operations with RedFlick Malware Delivery

Published October 3, 2026

Since January 2026, the Russian state-linked threat actor Star Blizzard has expanded its phishing campaign using large‑volume email lures, compromised web infrastructure, and a novel RedFlick delivery chain that inserts password‑protected ZIP/RAR archives into ongoing trusted email threads, ultimately deploying the CosmicPulse backdoor. Over 100 organizations across ≥13 campaigns in government, diplomacy, research, public policy, journalism, and finance—primarily in the US, UK, and allied NATO states—have been compromised, with single‑victim interaction sufficient for infection and persistence via scheduled tasks, registry Run keys, and service creation.

  • Incident Overview
  • ≥13 distinct phishing waves tracked since Jan 2026, affecting >100 organizations.
  • Targets include government, diplomacy, research, public policy, journalism, and finance sectors.
  • Primary geographic focus: United States, United Kingdom, and other NATO/allied states with Ukraine ties.
  • Delivers CosmicPulse backdoor via the RedFlick infection chain; one click can lead to full compromise.

  • Attack Vector & Campaign Mechanics

  • Uses fake event invitations (conference/webinar) as lures in spear‑phishing emails.
  • Malicious payloads delivered as password‑protected ZIP/RAR archives placed inside legitimate, ongoing email threads (conversation hijacking).
  • Archives contain base64‑encoded PowerShell scripts; RedFlick leverages compromised websites to host and serve these payloads.
  • Command‑and‑control (C2) infrastructure resides on legitimate but compromised web servers; persistence established via scheduled tasks, registry Run keys, and newly created services.

  • Threat Group Profile & Scale

  • Star Blizzard (also tracked as COLDRIVER) is a Russian state‑linked APT with a history of credential‑phishing and espionage.
  • Demonstrates high operational security by abusing trusted email conversations to bypass secure email gateways.
  • Campaign breadth: ≥13 waves, >100 victims, notable concentration in US/UK entities linked to Ukraine policy or support.
  • Aligns with strategic intelligence collection goals against Ukrainian‑related governmental, diplomatic, and research institutions.

  • Indicators of Compromise & Defensive Actions

  • IOCs: base64‑encoded PowerShell strings within archive attachments; unexpected ZIP/RAR files with passwords disclosed in the same email thread.
  • Network indicators: outbound HTTPS connections to compromised domains serving as C2; appearance of new scheduled tasks or services.
  • Detection: monitor email replies for archive attachments, enforce attachment sandboxing, block unsigned PowerShell execution, audit for abnormal task/service creation.
  • Mitigation: enforce MFA, disable macro execution, conduct phishing awareness focused on thread‑based lures, quarantine password‑protected archives until password validity verified.

  • Conclusion & Outlook

  • RedFlick reflects a shift toward trusted‑thread hijacking and archive‑based evasion to defeat traditional SEG and sandbox controls.
  • Expect continued refinement, potential expansion to additional sectors, and increased volume as the group scales infrastructure.
  • Defenders should prioritize email thread integrity monitoring, behavior‑based detection of post‑exploitation artifacts, and rapid isolation of suspicious archive payloads.

Related posts

  1. fieldeffect.com — Star Blizzard scales phishing operations with RedFlick malware delivery
  2. SecurityWeek — Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
  3. Microsoft Security Blog — Star Blizzard refines phishing and malware delivery with the RedFlick technique
  4. thehackernews.com — Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
  5. cyberscoop.com — Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
  6. The Record by Recorded Future — Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
  7. Dark Reading — Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
  8. SOCFortress — Microsoft Threat Intelligence Reports on NeedyMantis and Star Blizzard Cyber Threats
  9. Socprime
  10. Gurucul
  11. Cybersecurity-help

LINK COPIED TO CLIPBOARD