Star Blizzard Scales Phishing With “RedFlick”

Microsoft Security · High sophistication
Last updated September 30, 2026

Microsoft reports that the Russian state-linked actor Star Blizzard ran large-scale phishing campaigns in 2026 that use convincing lures like tax notices, fines, and “closed-door” event invitations. After a victim replies, the attacker sends a password-protected ZIP/RAR attachment that triggers a new “RedFlick” malware delivery flow to install the CosmicPulse backdoor with minimal user interaction.

How the attack worked

Microsoft reports that Star Blizzard shifted in 2026 from narrowly targeted spearphishing to larger-scale email campaigns reaching tens to hundreds of recipients per run. The workflow depends on a two-stage exchange: an initial email uses a lure such as a Ukrainian tax audit notice, a payment advice note, or an invitation to a closed-door policy event. Once the recipient replies, expressing interest or simply engaging with the message, the attacker follows up with a password-protected ZIP or RAR archive. The password itself is delivered as an image rather than as text, a tactic aimed at evading automated content scanning.

This follow-up archive triggers the RedFlick delivery flow, which Microsoft describes as reducing the number of actions a victim needs to take to a single interaction. RedFlick uses scheduled tasks to install the CosmicPulse backdoor and downloader with minimal further engagement from the target.

Why it succeeded

Several factors work together to make these campaigns effective. The lures are tailored to plausible, high-stakes contexts, tax notices for individuals in Ukraine, payment notices for finance staff, and confidential event invitations for policy and research audiences. The reply-first structure also builds a false sense of legitimacy: because the victim initiated further contact, the follow-up archive feels expected rather than unsolicited.

Star Blizzard also used accounts created on compromised websites to send phishing emails, rather than relying mainly on free email services. This can make sender domains look more credible on cursory inspection, since the message may not originate from a known throwaway address.

What to watch for

  • Emails that ask you to reply before sending an attachment, followed later by a password-protected ZIP or RAR file
  • Passwords for attachments delivered as images instead of plain text
  • Unexpected tax, fine, or payment notices with attachments rather than links to official portals
  • Invitations describing events as confidential or closed-door, especially when attributed to well-known think tanks or NGOs
  • Generic, broadly addressed messages sent to many recipients within an organization

How to build resistance

Defenders and employees should treat any workflow where an email exchange leads to a password-protected archive as high risk, verifying the sender through a separate trusted channel before opening anything. Confidential invitations from reputable organizations should be independently confirmed rather than taken at face value. Because sending infrastructure can include compromised legitimate websites, sender domain reputation alone should not be treated as proof of legitimacy. Finally, unexpected tax, fine, or payment-related emails with attachments warrant verification through official channels before any file is opened.

Key findings

  • Microsoft observed Star Blizzard shift in 2026 from targeted spearphishing to larger-scale email campaigns (tens to hundreds of messages per campaign).
  • Campaigns used specific lures/subjects including Ukrainian-language tax/fine notices and English-language invitations to “closed-door” policy/security events.
  • The attacker commonly waits for a reply, then sends a follow-up with a password-protected RAR/ZIP; the password is provided as an image.
  • Star Blizzard used compromised websites to create accounts for sending phishing emails, rather than relying mainly on free email services.
  • “RedFlick” reduces required victim actions to a single interaction and uses scheduled tasks to deploy the CosmicPulse backdoor/downloader.

Who’s being targeted

  • Commonly targeted roles: Executives and policy staff, Government affairs / public sector teams, NGO and think-tank staff, Finance and Accounts Payable, Researchers and analysts, Administrative assistants / coordinators who handle invitations.
  • Affected industries: Government, Non-profits / NGOs, Think tanks / policy organizations, Education / academia, Media, Financial services, Hospitality (hotels).
  • Attack channels: email.
  • Impersonated: Reputable think tank or NGO event organizer (e.g., Chatham House/IISS-themed invite), Ukrainian authorities, Finance/payment processing sender (payment notice theme).

Red flags to watch for

  • Password provided as an image (to evade scanning) for a compressed attachment
  • Workflow depends on you replying first, then receiving a protected archive
  • “Confidential/closed-door” framing creates urgency and reduces scrutiny
  • Unexpected “tax audit” notice sent by email with an attachment
  • Generic targeting (“unidentified Ukraine persons”) suggests mass mailing
  • Attachment-based lure rather than directing you to official channels/portals
  • Payment-themed attachment with password delivered via email
  • Message sent “to all targets” rather than a specific accountable owner
  • Password-in-image tactic intended to bypass automated scanning
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the RedFlick technique used by Star Blizzard?

RedFlick is a malware delivery method that reduces victim interaction to a single step, using scheduled tasks to deploy the CosmicPulse backdoor after the target opens a password-protected archive.

How does Star Blizzard get victims to open malicious attachments?

The attacker waits for a recipient to reply to an initial email, then sends a follow-up with a password-protected ZIP or RAR file, with the password provided as an image to evade scanning.

What lures does Star Blizzard use in these campaigns?

Observed lures include Ukrainian-language tax audit or fine notices, English-language invitations to closed-door policy events, and payment advice notices targeting finance staff.

Who is being targeted by these RedFlick campaigns?

Targets include government and NGO staff, think tank and academic researchers, media, finance and accounts payable employees, and administrative staff who handle invitations.

Read the video transcript

Imagine this in your inbox: “Invitation to the Chatham House London Conference 2026 – 9 July 2026.” Looks legit, right? This is Star Blizzard’s new RedFlick trick: you reply first, then they send a password‑protected ZIP or RAR, with the password shown only in an image. One click, and RedFlick quietly drops the CosmicPulse backdoor. Same playbook shows up as Ukrainian tax notices: “Повідомлення про результати податкової перевірки” with an attached RedFlick lure. It might even come from a real-looking domain, because the account on that site was compromised. If an email wants you to reply first and then open a password‑protected attachment, stop. Before you open anything, verify the sender through a trusted channel you already use.

Similar attacks

Star Blizzard Uses Fake Invites to Install Backdoor

Star Blizzard Uses Fake Invites to Install Backdoor

Microsoft reports Russia-linked Star Blizzard sent fake event invitations and other business notices to trick targets into opening disguised files that install a Windows backdoor. The campaigns targeted Ukraine-linked people and organizations and hit 100+ organizations, mainly in the U.S. and U.K.,…

September 29, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026