Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Citrix ADC, Gateway Zero-Days Under Active Attack
September 30, 2026
Google Chrome Update Patches 32 Security Flaws Across Platforms
September 30, 2026
Cloudflare Launches Post-Quantum CA with Merkle Tree Certificates for Faster TLS
September 30, 2026
Home/Threats/APT28 Targets Organizations With RedFlick Phishing Attacks
Threats

APT28 Targets Organizations With RedFlick Phishing Attacks

Key Takeaways The Russian state-sponsored APT28 group, also known as Star Blizzard, ColdRiver, or Callisto, has broadened its phishing operations using a new RedFlick delivery chain. Over 100...

David kimber
David kimber
September 30, 2026 4 Min Read
2 0

Key Takeaways

  • The Russian state-sponsored APT28 group, also known as Star Blizzard, ColdRiver, or Callisto, has broadened its phishing operations using a new RedFlick delivery chain.
  • Over 100 organizations, primarily in the U.S. and U.K., have been targeted between January and August 2026.
  • The campaign employs a multi-stage approach, initiating with benign-looking emails to establish trust before delivering password-protected archives containing malicious files.
  • Targeted sectors include government, diplomacy, research, public policy, journalism, and financial institutions involved in Ukraine-related work.
  • The attacks ultimately aim to deploy the CosmicPulse backdoor, granting persistent access to compromised Windows systems.

A sophisticated phishing campaign orchestrated by the Russian state-affiliated advanced persistent threat (APT) group APT28, also identified as Star Blizzard, ColdRiver, or Callisto, has expanded its reach, impacting over 100 organizations. This operation leverages a novel delivery method dubbed “RedFlick,” meticulously designed to circumvent traditional security measures by initiating seemingly innocuous email conversations.

Table Of Content

  • Key Takeaways
  • Russian Hackers Target 100+ Organizations
  • What You Should Do

This evolving threat, observed in at least 13 distinct campaigns from January through August 2026, predominantly targets entities within the United States and the United Kingdom. The affected organizations span critical sectors, including government, diplomatic missions, research institutions, public policy think tanks, journalism outlets, and financial groups with connections to Ukraine-related activities.

Analysts at Field Effect noted in a report shared with Cyber Security News (CSN) that this campaign signifies a strategic shift for Star Blizzard. The group is moving away from direct spear-phishing tactics towards broader initial-contact campaigns. This new approach enables the attackers to first identify and engage with recipients who show a willingness to interact before deploying any malicious payloads. Field Effect said in a report that compromised websites are being utilized to register accounts for distributing these phishing emails.

This adaptation underscores the group’s history of continuously refining its attack methodologies, which previously included malicious WhatsApp QR-code attacks targeting high-value individuals.

Russian Hackers Target 100+ Organizations

The initial phase of the RedFlick attack is characterized by an email devoid of any attachments, malware, or exploits. Instead, these messages are crafted to initiate a dialogue, often mimicking legitimate professional correspondence such as invitations, policy discussions, financial inquiries, research collaboration requests, or document sharing. The objective is to elicit a reply, which signals the recipient’s trust in the sender and opens the door to the subsequent, more malicious stages of the attack.

Upon receiving a reply, the attackers send a follow-up email containing a password-protected RAR or ZIP archive. Crucially, the password for this archive is embedded as an image within the email itself. This tactic serves a dual purpose: it hinders automated security solutions from inspecting the archive’s contents and lends an air of legitimacy to the attachment, as it arrives within an ongoing, seemingly normal conversation. This method of using password-protected archives to bypass email scanning is a known technique for reducing visibility to security products.

Once opened, these archives may contain either a VHDX virtual disk image or a Windows shortcut (LNK file) cleverly disguised as a PDF document. These files, when executed, trigger scripts and leverage legitimate Windows utilities to download additional malicious components from infrastructure controlled by the attackers. This technique of concealing harmful actions behind a decoy document-like shortcut is reminiscent of earlier weaponized PDF and LNK attacks.

Beginning in April, the RedFlick installers were observed performing several critical actions. They established scheduled tasks for persistence, gathered basic system information, enabled WebDAV access, and retrieved the necessary files to install the CosmicPulse backdoor. Scheduled tasks provide attackers with a reliable mechanism to re-execute code, while WebDAV is a standard Windows protocol for accessing remote files, further aiding in lateral movement and data exfiltration.

By July, the attackers had introduced an additional layer of obfuscation. They began nesting a password-protected RAR archive inside a ZIP file. The shortcut within this nested archive would then download a PDF containing encoded data. PowerShell was subsequently used to extract and execute this data, leading to the installation of an MSI installer. This multi-layered approach further distances the visible, benign-looking document from the underlying malicious processes, making detection even more challenging.

What You Should Do

  • Scrutinize Email Threads: Be vigilant for encrypted RAR or ZIP archives that arrive following initial emails devoid of attachments, particularly if the sender claims an attachment was omitted or provides a password within the conversation.
  • Isolate and Review Encrypted Archives: Where operational policies permit, implement enhanced review procedures for encrypted archives that cannot be automatically inspected before they reach end-user endpoints.
  • Monitor for Suspicious Activity Chains: Correlate events such as archive extraction, VHDX mounting, LNK file execution, MSI installer activity, PowerShell commands, WebDAV connections, scheduled task creation, and unusual external network connections.
  • Verify Unexpected Requests: Always independently verify unexpected requests or attachments via a known, alternative communication channel (e.g., a phone call) before interacting with them, especially for organizations involved in Ukraine-related policy, research, diplomacy, journalism, or finance.
  • Incident Response Protocol: If an execution is suspected, immediately isolate the affected device, preserve the entire email thread and the original archive, and thoroughly inspect scheduled tasks and other persistence mechanisms.
  • Forensic Analysis: Review process and network logs to identify the infection vector and propagation path. Additionally, examine the compromised user’s accounts, active sessions, mailbox rules, and recent messages for signs of further targeting or compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurity

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

AI Coding Agents Leak 13,000+ Internal Screenshots from 300+ Companies on GitHub

Next Post

PaperPhone Headless Browser Network Impersonates 75,000 Mobile Devices Across 43 Countries

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
APT28 Targets Organizations With RedFlick Phishing Attacks
September 30, 2026
AI Coding Agents Leak 13,000+ Internal Screenshots from 300+ Companies on GitHub
September 30, 2026
Critical Microsoft 365 Flaw Let Attackers Access Accounts
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us