Skip Navigation

September 29, 2026 |

Star Blizzard scales phishing operations with RedFlick malware delivery

Loading table of contents...

At a glance:

  • Russian state-linked threat actor Star Blizzard expanded its phishing operations throughout 2026, combining larger initial-contact campaigns, compromised web infrastructure, and a new RedFlick delivery chain that ultimately deployed the CosmicPulse backdoor.

  • The activity targeted organizations involved in government, diplomacy, research, public policy, journalism, and financial activities connected to Ukraine, with more than 100 organizations affected across at least 13 campaigns.
  • Password-protected archives delivered through ongoing email conversations create opportunities for malicious files to reach endpoints with reduced visibility from some email security controls, making endpoint monitoring and user-driven delivery investigations increasingly important. 

Threat summary

On September 29, 2026, Microsoft Threat Intelligence published a report detailing how Star Blizzard expanded and adapted its phishing operations throughout 2026. The threat actor shifted from highly targeted spear-phishing campaigns to broader initial-contact operations, used accounts created on compromised websites to distribute phishing emails, and updated its malware delivery process to support deployment of the CosmicPulse backdoor. Between January and August 2026, Microsoft observed at least 13 campaigns affecting more than 100 organizations, primarily in the United States and United Kingdom.

One of the more notable developments was a delivery technique designed to move malicious files through email security controls and onto target systems. Rather than including a malicious attachment in the initial message, Star Blizzard first attempted to establish a conversation with the recipient. After receiving a reply, the threat actor sent a follow-up email containing a password-protected RAR or ZIP archive. The password was provided as an image within the message, while the archive contained the files used to initiate the RedFlick malware delivery chain.

The technique limits defensive visibility at multiple stages. The initial email contains no malware, attachment, or exploit, reducing obvious indicators of malicious activity. The password-protected archive can also prevent security products that cannot decrypt protected files from examining their contents before delivery. Because the archive arrives as part of an ongoing conversation, recipients may be more likely to view it as a legitimate document exchange rather than a phishing attempt.

Once extracted, the archive initiates a multi-stage infection process. Depending on the campaign, it contained virtual hard disk (VHDX) files or Windows shortcut (LNK) files disguised as PDF documents. These files launched scripts and legitimate Windows utilities that retrieved additional components from threat actor-controlled infrastructure. Beginning in April 2026, RedFlick installers created scheduled tasks that collected basic host information, enabled Web Distributed Authoring and Versioning (WebDAV) access, and retrieved components used to install the CosmicPulse backdoor.

In July 2026, Star Blizzard introduced an additional layer by placing a password-protected RAR archive inside a ZIP file. The enclosed shortcut downloaded a PDF containing encoded data that PowerShell extracted and executed to retrieve an MSI installer. Microsoft observed RedFlick communicating with remote infrastructure, creating scheduled tasks, and deploying CosmicPulse in at least one incident, providing persistent access to the affected Windows endpoint.

Analysis

Historically, the Star Blizzard was known for highly targeted spear-phishing operations against carefully selected individuals. The 2026 activity demonstrates a move toward larger-scale engagement campaigns designed to identify responsive targets before delivering malicious content. This approach allows the threat actor to build trust, filter for engaged recipients, and reserve the malware delivery stage for individuals who have already interacted with the phishing operation.

The delivery method is effective because it relies on normal business behaviour like conference invitations, policy discussions, financial correspondence, research collaboration, and document sharing. By embedding the malware delivery process within these workflows, the threat actor leverages user trust and established communication patterns.

The use of password-protected archives can reduce visibility into attachment contents before delivery, increasing the importance of endpoint monitoring. In environments where encrypted attachments cannot be fully inspected, archive extraction, VHDX mounting, shortcut execution, PowerShell activity, and scheduled-task creation may provide the earliest opportunities to detect the RedFlick infection chain.

Mitigations

Review email telemetry for password-protected RAR or ZIP archives delivered after earlier attachment-free messages, particularly when the sender claims an attachment was omitted or provides a password as part of the conversation. Identifying recipients who received, extracted, mounted, or opened these files can help responders distinguish between email delivery and successful execution. Where business requirements permit, route encrypted archives that cannot be inspected through additional review processes to reduce the likelihood that unexamined content reaches endpoints.

Monitor systems for archive extraction followed by execution of VHDX files, LNK files, MSI installers, PowerShell, WebDAV activity, scheduled-task creation, or connections to unfamiliar external infrastructure. Correlating these events provides greater visibility into the RedFlick delivery chain than attachment monitoring alone. If execution may have occurred, isolate the affected system, preserve the email thread and original archive, review scheduled tasks and persistence mechanisms, collect process and network telemetry, and investigate the affected user's accounts, active sessions, mailbox rules, and recent communications for signs of additional compromise or follow-on targeting.

 

 

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up