Star Blizzard’s RedFlick Phish Uses VHDX Trap

Security Week Feed · High sophistication
Last updated October 1, 2026

Microsoft reports real-world Star Blizzard phishing campaigns where victims who engage with an initial email receive a follow-up message containing a password-protected ZIP/RAR attachment. The attachment chain hides a malicious shortcut disguised as a PDF, opening a decoy file while quietly downloading and installing additional malware. Targets included Ukrainian individuals and institutions plus NGOs, think tanks, governments, and financial institutions supporting Ukraine.

How the Attack Worked

Star Blizzard's phishing operation relied on a staged, reply-first workflow rather than a single malicious email. The initial message was crafted to look like it came from inside the target organization, or from Ukrainian authorities or a reputable think tank or NGO, and simply asked the recipient to confirm receipt or engage in conversation. Only after the target replied did the attacker send a second email containing a password-protected ZIP or RAR archive. That archive held the actual payload: a VHDX container with a shortcut file disguised as a PDF. Clicking the fake PDF opened a decoy document while quietly executing a background script. Later variants of the chain fetched an MSI installer and used scheduled tasks for persistence, with some campaigns in July using a multistage PowerShell execution chain triggered by the malicious shortcut.

Why It Succeeded

The two-step delivery model is effective because it defeats automated scanning: security tools analyzing the first email see nothing malicious, since the actual archive only arrives after a human has replied and demonstrated engagement. The password-protected archive adds another layer of evasion, since scanners generally cannot inspect encrypted file contents. Spoofing an internal sender or a trusted Ukrainian authority or NGO also lowers suspicion, since recipients are primed to expect legitimate correspondence from those sources.

What to Watch For

  • Emails that ask for a simple reply or confirmation before any attachment is sent
  • A follow-up message containing a password-protected ZIP or RAR archive
  • A "document" delivered as a VHDX container rather than a standard PDF or Office file
  • A file that looks like a PDF but is actually a shortcut (LNK) that opens a decoy while running something in the background
  • Internal-looking emails with unusual or unexpected attachment types

How to Build Resistance

Organizations supporting Ukraine, including governments, NGOs, think tanks, financial institutions, and academic groups, should train staff to treat "reply-first" emails with caution, since the real payload often only appears after engagement. Staff should verify password-protected archives through a separate trusted channel before opening them, and should never open unfamiliar container formats like VHDX. Reporting unusual attachment types to security teams, rather than opening them to "check quickly," closes off the critical step where the RedFlick chain executes its background script and begins the malware installation process.

Key findings

  • Star Blizzard ran phishing campaigns that only delivered the malware after the victim replied to the initial email (two-step workflow).
  • The follow-up email included a password-protected RAR/ZIP archive used to evade scanning and deliver the payload.
  • Campaigns used a VHDX container holding a malicious LNK disguised as a PDF; clicking it opened a decoy while executing a background script.
  • The chain fetched an MSI installer and used scheduled tasks for persistence; later variants used PowerShell in a multistage chain.
  • Targets included Ukrainian individuals/institutions and international NGOs, think tanks, governments, and financial institutions supporting Ukraine.
  • The actor created accounts on compromised websites and sent tens to hundreds of phishing emails per campaign.

Who’s being targeted

  • Commonly targeted roles: Executive leadership, Executive assistants, Finance, Government affairs / policy, NGO program teams, Researchers / analysts, All staff in organizations supporting Ukraine.
  • Affected industries: Government, Nonprofits/NGOs, Think tanks, Financial services, Academia, Defense.
  • Attack channels: email.
  • Impersonated: Ukrainian authorities or a reputable think tank/NGO (or an internal sender within the target organization), Internal colleague within the organization (email crafted to look internal).

Red flags to watch for

  • Sender waits for a reply before sending the real attachment (staged delivery).
  • Password-protected ZIP/RAR used to bypass email scanning.
  • Unexpected “document” arrives as an archive rather than a normal PDF/Office file.
  • “PDF” is actually a shortcut file (LNK) disguised as a document.
  • Unusual attachment type (VHDX container) for a routine document share.
  • Document opens a decoy while something else runs in the background.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What makes Star Blizzard's phishing campaign a two-step attack?

The attacker only sends the malicious attachment after the target replies to an initial, seemingly harmless email, which helps the payload evade automated scanning that only sees the first message.

Why do these emails use password-protected ZIP or RAR files?

Password-protected archives prevent email security scanners from inspecting the contents, letting the malicious file bypass automated detection before a human opens it.

What is the VHDX trap mentioned in the RedFlick chain?

Star Blizzard attached a Virtual Hard Disk (VHDX) container holding a shortcut file disguised as a PDF; clicking it opens a decoy document while quietly running a background script that installs malware.

Who were the main targets of this campaign?

Targets included Ukrainian individuals and institutions, plus NGOs, think tanks, governments, and financial institutions supporting Ukraine.

Read the video transcript

You get an email that looks internal: “Hi, can you confirm receipt? I’ll send the document in a protected archive once you reply.” This is Star Blizzard’s RedFlick trick: once you reply, they send a password‑protected ZIP or RAR that our scanners can’t see into, holding a VHDX file with a fake PDF inside. Click that “PDF” and it opens a harmless-looking decoy, while in the background it pulls down an MSI installer or PowerShell chain and sets scheduled tasks to stay on your machine. If any “internal” email makes you reply first, then sends a password‑protected ZIP or a weird VHDX “document,” stop and report it to security, don’t open it.

Similar attacks

Star Blizzard Uses Fake Invites to Install Backdoor

Star Blizzard Uses Fake Invites to Install Backdoor

Microsoft reports Russia-linked Star Blizzard sent fake event invitations and other business notices to trick targets into opening disguised files that install a Windows backdoor. The campaigns targeted Ukraine-linked people and organizations and hit 100+ organizations, mainly in the U.S. and U.K.,…

September 29, 2026
Star Blizzard Scales Phishing With “RedFlick”

Star Blizzard Scales Phishing With “RedFlick”

Microsoft reports that the Russian state-linked actor Star Blizzard ran large-scale phishing campaigns in 2026 that use convincing lures like tax notices, fines, and “closed-door” event invitations. After a victim replies, the attacker sends a password-protected ZIP/RAR attachment that triggers a…

September 29, 2026
Phish Drops MSP360, Then Installs ScreenConnect

Phish Drops MSP360, Then Installs ScreenConnect

Microsoft reported real phishing campaigns that trick users into running a legitimate MSP360 remote-management installer disguised as meeting invites, PDFs, and software updates. After MSP360 is installed, attackers use it to silently install ScreenConnect as a second remote-access path, then use…

September 30, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
“Case Documents” Lure Hits Law Firm via LNK

“Case Documents” Lure Hits Law Firm via LNK

Researchers reported a real spear‑phishing intrusion against a law firm where attackers sent a message with a link to an encrypted archive. The archive contained a Windows shortcut (LNK) disguised as “Case Documents,” and running it launched a multi‑stage loader (“HollowFrame”) that ultimately…

July 31, 2026