Microsoft reports that the Russian state-linked actor Star Blizzard ran large-scale phishing campaigns in 2026 that use convincing lures like tax notices, fines, and “closed-door” event invitations. After a victim replies, the attacker sends a password-protected ZIP/RAR attachment that triggers a new “RedFlick” malware delivery flow to install the CosmicPulse backdoor with minimal user interaction.
How the attack worked
Microsoft reports that Star Blizzard shifted in 2026 from narrowly targeted spearphishing to larger-scale email campaigns reaching tens to hundreds of recipients per run. The workflow depends on a two-stage exchange: an initial email uses a lure such as a Ukrainian tax audit notice, a payment advice note, or an invitation to a closed-door policy event. Once the recipient replies, expressing interest or simply engaging with the message, the attacker follows up with a password-protected ZIP or RAR archive. The password itself is delivered as an image rather than as text, a tactic aimed at evading automated content scanning.
This follow-up archive triggers the RedFlick delivery flow, which Microsoft describes as reducing the number of actions a victim needs to take to a single interaction. RedFlick uses scheduled tasks to install the CosmicPulse backdoor and downloader with minimal further engagement from the target.
Why it succeeded
Several factors work together to make these campaigns effective. The lures are tailored to plausible, high-stakes contexts, tax notices for individuals in Ukraine, payment notices for finance staff, and confidential event invitations for policy and research audiences. The reply-first structure also builds a false sense of legitimacy: because the victim initiated further contact, the follow-up archive feels expected rather than unsolicited.
Star Blizzard also used accounts created on compromised websites to send phishing emails, rather than relying mainly on free email services. This can make sender domains look more credible on cursory inspection, since the message may not originate from a known throwaway address.
What to watch for
- Emails that ask you to reply before sending an attachment, followed later by a password-protected ZIP or RAR file
- Passwords for attachments delivered as images instead of plain text
- Unexpected tax, fine, or payment notices with attachments rather than links to official portals
- Invitations describing events as confidential or closed-door, especially when attributed to well-known think tanks or NGOs
- Generic, broadly addressed messages sent to many recipients within an organization
How to build resistance
Defenders and employees should treat any workflow where an email exchange leads to a password-protected archive as high risk, verifying the sender through a separate trusted channel before opening anything. Confidential invitations from reputable organizations should be independently confirmed rather than taken at face value. Because sending infrastructure can include compromised legitimate websites, sender domain reputation alone should not be treated as proof of legitimacy. Finally, unexpected tax, fine, or payment-related emails with attachments warrant verification through official channels before any file is opened.
Key findings
- Microsoft observed Star Blizzard shift in 2026 from targeted spearphishing to larger-scale email campaigns (tens to hundreds of messages per campaign).
- Campaigns used specific lures/subjects including Ukrainian-language tax/fine notices and English-language invitations to “closed-door” policy/security events.
- The attacker commonly waits for a reply, then sends a follow-up with a password-protected RAR/ZIP; the password is provided as an image.
- Star Blizzard used compromised websites to create accounts for sending phishing emails, rather than relying mainly on free email services.
- “RedFlick” reduces required victim actions to a single interaction and uses scheduled tasks to deploy the CosmicPulse backdoor/downloader.
Who’s being targeted
- Commonly targeted roles: Executives and policy staff, Government affairs / public sector teams, NGO and think-tank staff, Finance and Accounts Payable, Researchers and analysts, Administrative assistants / coordinators who handle invitations.
- Affected industries: Government, Non-profits / NGOs, Think tanks / policy organizations, Education / academia, Media, Financial services, Hospitality (hotels).
- Attack channels: email.
- Impersonated: Reputable think tank or NGO event organizer (e.g., Chatham House/IISS-themed invite), Ukrainian authorities, Finance/payment processing sender (payment notice theme).
Red flags to watch for
- Password provided as an image (to evade scanning) for a compressed attachment
- Workflow depends on you replying first, then receiving a protected archive
- “Confidential/closed-door” framing creates urgency and reduces scrutiny
- Unexpected “tax audit” notice sent by email with an attachment
- Generic targeting (“unidentified Ukraine persons”) suggests mass mailing
- Attachment-based lure rather than directing you to official channels/portals
- Payment-themed attachment with password delivered via email
- Message sent “to all targets” rather than a specific accountable owner
- Password-in-image tactic intended to bypass automated scanning
Frequently asked questions
What is the RedFlick technique used by Star Blizzard?
RedFlick is a malware delivery method that reduces victim interaction to a single step, using scheduled tasks to deploy the CosmicPulse backdoor after the target opens a password-protected archive.
How does Star Blizzard get victims to open malicious attachments?
The attacker waits for a recipient to reply to an initial email, then sends a follow-up with a password-protected ZIP or RAR file, with the password provided as an image to evade scanning.
What lures does Star Blizzard use in these campaigns?
Observed lures include Ukrainian-language tax audit or fine notices, English-language invitations to closed-door policy events, and payment advice notices targeting finance staff.
Who is being targeted by these RedFlick campaigns?
Targets include government and NGO staff, think tank and academic researchers, media, finance and accounts payable employees, and administrative staff who handle invitations.
Read the video transcript
Imagine this in your inbox: “Invitation to the Chatham House London Conference 2026 – 9 July 2026.” Looks legit, right? This is Star Blizzard’s new RedFlick trick: you reply first, then they send a password‑protected ZIP or RAR, with the password shown only in an image. One click, and RedFlick quietly drops the CosmicPulse backdoor. Same playbook shows up as Ukrainian tax notices: “Повідомлення про результати податкової перевірки” with an attached RedFlick lure. It might even come from a real-looking domain, because the account on that site was compromised. If an email wants you to reply first and then open a password‑protected attachment, stop. Before you open anything, verify the sender through a trusted channel you already use.