Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations.

The campaign replaces an obvious malicious attachment with a conversation that looks like ordinary professional correspondence.

The activity was recorded in at least 13 campaigns from January through August 2026, chiefly affecting organizations in the United States and United Kingdom.

Government, diplomacy, research, public policy, journalism, and financial groups with Ukraine-related work were among the targets.

Analysts at Field Effect noted that the operation reflects a wider shift by Star Blizzard, also known as ColdRiver or Callisto, from narrow spear-phishing toward larger initial-contact campaigns. The change lets operators identify people willing to engage before they send the harmful files.

Field Effect said in a report shared with Cyber Security News (CSN) that compromised websites were used to create accounts for distributing phishing emails.

The approach builds on the group’s history of adapting its lures, including malicious WhatsApp QR-code attacks aimed at high-interest targets.

Russian Hackers Target 100+ Organizations

The first message contains no attachment, malware, or exploit. Instead, attackers try to start a discussion, often exploiting the normal rhythm of invitations, policy exchanges, financial correspondence, research collaboration, or document sharing.

A reply signals that the recipient may trust the sender and opens the door to the next stage. The follow-up message carries a password-protected RAR or ZIP archive, while its password appears as an image in the email.

This arrangement can stop security products from inspecting the contents and makes the archive feel more credible because it arrives inside an existing exchange. Similar password-protected archive phishing tactics have been used to reduce email scanning visibility.

Once opened, the archive may contain a VHDX virtual disk or a Windows shortcut, known as an LNK file, disguised as a PDF document. The files run scripts and legitimate Windows utilities to download further components from attacker-controlled infrastructure.

This abuse of a document-like shortcut resembles earlier weaponized PDF and LNK attacks that hid harmful actions behind a decoy file.

Beginning in April, RedFlick installers created scheduled tasks, gathered basic system details, enabled WebDAV access, and fetched material used to install the CosmicPulse backdoor.

Scheduled tasks can give an attacker a reliable way to rerun code, while WebDAV is a Windows-supported method for accessing remote files.

In July, the operators added another layer by placing a password-protected RAR archive inside a ZIP file. Its shortcut downloaded a PDF containing encoded data.

PowerShell then extracted and ran that data to obtain an MSI installer, further separating the visible document from the malicious process.

Detection and Response Priorities

Microsoft observed RedFlick communicate with remote infrastructure, create scheduled tasks, and deploy CosmicPulse in at least one incident.

That sequence can leave the attacker with persistent access to a Windows device, even after the original phishing email has disappeared from a user’s immediate view.

Defenders should review email logs for encrypted RAR or ZIP archives that arrive after earlier attachment-free messages, especially when a sender says an attachment was omitted or supplies a password in the conversation.

Teams should identify recipients who received, extracted, mounted, or opened the files, separating delivery from actual execution. Where operations allow it, encrypted archives that cannot be inspected should receive extra review before reaching endpoints.

Security teams should also correlate archive extraction with VHDX mounting, LNK execution, MSI installers, PowerShell, WebDAV activity, scheduled-task creation, and unfamiliar external connections.

If execution is suspected, responders should isolate the device, preserve the email thread and original archive, and inspect scheduled tasks and other persistence settings.

Process and network records can reveal the infection path, while reviewing the user’s accounts, active sessions, mailbox rules, and recent messages may expose further targeting.

The campaign shows why a clean-looking first email is not evidence of safety. Verifying unexpected requests through a known contact channel remains important, particularly for organizations handling Ukraine-related policy, research, diplomacy, journalism, or finance.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack appeared first on Cyber Security News.