Star Blizzard Scales Phishing With “RedFlick”

The Record · High sophistication
Last updated October 1, 2026

Microsoft reports that the Russia-linked group Star Blizzard expanded from highly targeted spear-phishing to larger email campaigns aimed at Ukraine supporters globally. Lures included tax-audit/unpaid-fine notices and fake conference invitations, followed by a password-protected archive that installs malware with just one click.

How the campaign unfolded

Star Blizzard, also tracked as Callisto or ColdRiver and linked to Russia's FSB, shifted from narrowly targeted spear-phishing to broader email campaigns sent in batches of tens or hundreds at a time. Early campaigns in January and February targeted users of the Ukrainian email provider Ukr.net, impersonating Ukrainian authorities with claims that the recipient faced a tax audit or had an unpaid fine. Beginning in March, the group broadened its targeting beyond Ukraine, using fake invitations to conferences or events supposedly organized by reputable think tanks or NGOs. In some cases, several people at the same organization were targeted, with messages disguised as internal communications.

The follow-up infection chain

Once a victim replies to one of these initial lures, Star Blizzard sends a follow-up containing a password-protected archive. Opening a file inside that archive triggers RedFlick, which uses scheduled tasks on the victim's computer to install the group's CosmicPulse backdoor while making the activity harder to detect. Notably, this method requires only one action from the victim, a simpler path to compromise than the group's earlier approach.

Why this scales so effectively

This attack succeeds because it layers believable pretexts on top of social engineering rather than relying on technical exploits. Threats of a tax audit or fine create urgency that pushes recipients to respond without verifying the sender. Conference invitations exploit professional curiosity and the credibility people associate with think tanks and NGOs. Using accounts created on compromised websites, rather than only impersonating free webmail providers, also helps the lures appear more legitimate. Once a reply is sent, the password-protected archive can slip past some automated scanning, and the single-click installation reduces the number of decisions a victim has to make before compromise occurs.

What defenders should watch for

  • Unsolicited emails threatening an audit or fine that pressure quick action
  • Sender addresses that do not match official government domains
  • Unexpected conference or event invitations asking you to reply or continue an email thread
  • Messages styled as internal communications sent to multiple coworkers
  • Password-protected archives arriving after you've replied to an email thread

Building organizational resistance

Staff across government, NGO, think tank, finance, and policy roles should treat replies to unsolicited audit, fine, or invitation emails as the first risk point, not just attachment handling. Verify claims of fines or audits through known official channels rather than by replying. Train employees to escalate password-protected archives to IT or security for inspection instead of opening them directly, and reinforce that an internal-looking email does not guarantee a legitimate sender, especially when multiple colleagues receive similar messages.

Key findings

  • Star Blizzard (aka Callisto/ColdRiver), linked to Russia’s FSB, expanded to larger-scale phishing campaigns (“tens or hundreds of emails at a time”).
  • Early 2026 campaigns targeted Ukr.net users with messages impersonating Ukrainian authorities about “a tax audit” or “an unpaid fine.”
  • From March, targeting broadened beyond Ukraine with “fake invitations to conferences or events supposedly organized by reputable think tanks or NGOs,” including emails disguised as internal communications.
  • Attackers used “accounts created on compromised websites” rather than only free webmail impersonation.
  • After a victim replies, the attacker sends a “password-protected archive”; opening it triggers “RedFlick,” which uses scheduled tasks to install the “CosmicPulse backdoor.”
  • The newer malware-delivery method “requires only one action from the victim,” making compromise easier than the prior “ClickFix” approach.

Who’s being targeted

  • Commonly targeted roles: All employees (NGOs/government/think tanks), Executives and executive assistants, Finance and Legal/Compliance, Public affairs/Policy teams, IT and Helpdesk (triage of suspicious attachments).
  • Affected industries: Government, Nonprofits/NGOs, Think tanks, International affairs/Policy organizations, Financial institutions.
  • Attack channels: email.
  • Impersonated: Ukrainian authorities (government/tax or fines office), Reputable think tank or NGO (conference organizer), Same person/organization from the earlier email thread.

Red flags to watch for

  • Unexpected threat of audit/fine sent via email
  • Sender account not from an official government domain (may be an account created on a compromised site)
  • Pressure to respond quickly to avoid penalties
  • Unsolicited invitation with vague logistics or urgency
  • Message appears to come from a reputable organization but sender is unusual or recently created
  • Multiple people at the same organization targeted with “internal” style wording
  • Password-protected archive sent after you reply (common to bypass scanning)
  • Unexpected attachment type/archived file requiring you to open an internal file
  • Email thread escalates to executing/opening files rather than normal coordination
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Who is Star Blizzard and what did they change in their attacks?

Star Blizzard, also known as Callisto or ColdRiver and linked to Russia's FSB, expanded from highly targeted spear-phishing to larger campaigns sending tens or hundreds of emails at a time.

What lures did Star Blizzard use in these campaigns?

Early campaigns impersonated Ukrainian authorities with claims of a tax audit or unpaid fine, while later campaigns used fake invitations to conferences or events supposedly organized by reputable think tanks or NGOs.

How does the RedFlick malware get installed?

After a victim replies to the initial phishing email, the attacker sends a password-protected archive. Opening a file inside it triggers RedFlick, which uses scheduled tasks to install the CosmicPulse backdoor, requiring only one action from the victim.

Why is this attack harder to detect than before?

The new delivery method requires only one action from the victim, compared to the group's prior approach, and the password-protected archive can help the malicious file bypass email scanning.

Read the video transcript

You get an email: “Notice: You are subject to a tax audit” or “unpaid fine.” Looks urgent, looks official… and it’s a trap. This is Star Blizzard using their RedFlick trick: you reply, they send a password‑protected archive, you open it once, and it quietly installs their CosmicPulse backdoor. Same move with fake conference invites: “Invitation: Conference registration details” from a think tank or NGO, or even phrased like an internal email, all pushing you to reply so they can send that archive. If any audit, fine, or invite email leads to a password‑protected archive, stop and forward it to IT or Security, do not open it.

Similar attacks

Star Blizzard Scales Phishing With “RedFlick”

Star Blizzard Scales Phishing With “RedFlick”

Microsoft reports that the Russian state-linked actor Star Blizzard ran large-scale phishing campaigns in 2026 that use convincing lures like tax notices, fines, and “closed-door” event invitations. After a victim replies, the attacker sends a password-protected ZIP/RAR attachment that triggers a…

September 29, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Star Blizzard’s RedFlick Phish Uses VHDX Trap

Star Blizzard’s RedFlick Phish Uses VHDX Trap

Microsoft reports real-world Star Blizzard phishing campaigns where victims who engage with an initial email receive a follow-up message containing a password-protected ZIP/RAR attachment. The attachment chain hides a malicious shortcut disguised as a PDF, opening a decoy file while quietly…

September 30, 2026
Star Blizzard Uses Fake Invites to Install Backdoor

Star Blizzard Uses Fake Invites to Install Backdoor

Microsoft reports Russia-linked Star Blizzard sent fake event invitations and other business notices to trick targets into opening disguised files that install a Windows backdoor. The campaigns targeted Ukraine-linked people and organizations and hit 100+ organizations, mainly in the U.S. and U.K.,…

September 29, 2026
Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026