The recap describes a real phishing operation by the Russia-linked group Star Blizzard, which used email “invitations” to trick targets into engaging and then opening a password-protected archive. The approach is designed to reduce friction, only one click/open action is needed, making it easier for busy people to fall for it.
How the Attack Worked
This campaign relied on a two-stage phishing approach. The first email masqueraded as an invitation, designed to start a conversation and build enough trust that the recipient would reply. Once a target responded, Star Blizzard sent a follow-up message containing a password-protected archive. Opening that archive triggered the infection chain, which was built to deploy a custom backdoor through scheduled tasks set up via the RedFlick technique.
What makes this flow notable is its simplicity from the attacker's perspective. Rather than requiring multiple clicks, downloads, or credential entries, the infection only needed a single user interaction, opening the archive, to succeed. That single-action design reduces friction in the compromise process and increases the odds that a distracted or busy employee will complete the step without pausing to question it.
Why It Succeeded
The invitation pretext works because it taps into ordinary professional behavior. Executives, executive assistants, and policy or international program staff regularly receive invitations to events, meetings, and conferences as part of their normal workload. An email that looks like one more invitation does not immediately stand out as suspicious, especially when it does not ask for anything unusual on the first contact.
The follow-up password-protected archive adds another layer of success for the attacker. Because the file is encrypted, many security scanners cannot inspect its contents before delivery, and the victim has already been primed to expect something related to the invitation they responded to. This sequencing, invitation first, payload second, lowers suspicion at each step rather than asking for everything at once.
What to Watch For
- Unexpected invitation emails that try to start a conversation before revealing any real content or attachment
- A follow-up message that arrives only after a reply, containing a password-protected archive
- Pressure to take one quick action, like opening an archive, to see event details or confirm participation
- Any workflow that feels unusually simple or frictionless for something involving an unfamiliar sender
Building Resistance
Organizations in government, NGOs, think tanks, and policy-focused education settings should treat unsolicited invitation emails with the same scrutiny as any other unexpected request. Verifying the sender through a trusted channel before replying or opening any attachment is a reasonable baseline step, particularly for staff who regularly interact with external partners and event organizers.
Teams should also recognize that password-protected archives are commonly used to conceal malicious content from automated scanning, so their presence in an unsolicited email deserves extra caution regardless of how legitimate the surrounding conversation appears. Finally, awareness training should emphasize that a workflow requiring only a single action is not automatically safer; many modern attacks are deliberately designed to succeed with minimal user interaction, which is exactly what made this RedFlick infection chain effective against its targets.
Key findings
- Star Blizzard used phishing emails disguised as “invitations” to start the interaction and then sent a follow-up with a password-protected archive.
- The infection flow was changed to require only a single user interaction, lowering the barrier to compromise.
- Targets included Ukrainian individuals and institutions plus international NGOs, think tanks, and governments tied to international policy.
Who’s being targeted
- Commonly targeted roles: Executives, Executive assistants, Public affairs / communications, Policy / international programs, NGO staff, Government staff.
- Affected industries: Government, Nonprofits/NGOs, Think tanks / policy organizations, Education (universities).
- Attack channels: email.
- Impersonated: An events organizer or partner organization sending an invitation.
Red flags to watch for
- Unexpected invitation email that tries to start a conversation first
- Follow-up message includes a password-protected archive
- Pressure to take a single quick action (open the archive) to view details
Frequently asked questions
What is the Star Blizzard invitation phishing technique?
Star Blizzard sends phishing emails disguised as invitations to start a conversation, then follows up with a password-protected archive that triggers malware once opened.
Why are password-protected archives dangerous in phishing emails?
Password-protected archives can hide malicious content from email security scanners, and in this campaign they were used to trigger the infection chain once opened.
Who was targeted by this Star Blizzard campaign?
Targets included Ukrainian individuals and institutions, along with international NGOs, think tanks, and governments involved in international policy.
Why is a single-click infection flow more dangerous?
Reducing the attack to one user action, like opening an archive, lowers the barrier to compromise and makes it easier for busy or distracted people to fall for it.
Read the video transcript
You get an email: subject line just says “Invitation.” Looks like a partner org inviting you to an event. Behind the scenes, this is Star Blizzard using a technique called RedFlick. Once you reply, they send a password‑protected archive that silently kicks off malware called CosmicPulse. Here’s the trick: the whole RedFlick attack only needs one quick action from you, open that archive. One click, and they’ve got a backdoor into your system. If you get an unexpected invitation that comes with a password‑protected archive, stop. Call or message the supposed sender on a trusted channel before you open anything.