APT28 Targets Organizations With RedFlick Phishing Attacks
Key Takeaways The Russian state-sponsored APT28 group, also known as Star Blizzard, ColdRiver, or Callisto, has broadened its phishing operations using a new RedFlick delivery chain. Over 100...
Key Takeaways
- The Russian state-sponsored APT28 group, also known as Star Blizzard, ColdRiver, or Callisto, has broadened its phishing operations using a new RedFlick delivery chain.
- Over 100 organizations, primarily in the U.S. and U.K., have been targeted between January and August 2026.
- The campaign employs a multi-stage approach, initiating with benign-looking emails to establish trust before delivering password-protected archives containing malicious files.
- Targeted sectors include government, diplomacy, research, public policy, journalism, and financial institutions involved in Ukraine-related work.
- The attacks ultimately aim to deploy the CosmicPulse backdoor, granting persistent access to compromised Windows systems.
A sophisticated phishing campaign orchestrated by the Russian state-affiliated advanced persistent threat (APT) group APT28, also identified as Star Blizzard, ColdRiver, or Callisto, has expanded its reach, impacting over 100 organizations. This operation leverages a novel delivery method dubbed “RedFlick,” meticulously designed to circumvent traditional security measures by initiating seemingly innocuous email conversations.
Table Of Content
This evolving threat, observed in at least 13 distinct campaigns from January through August 2026, predominantly targets entities within the United States and the United Kingdom. The affected organizations span critical sectors, including government, diplomatic missions, research institutions, public policy think tanks, journalism outlets, and financial groups with connections to Ukraine-related activities.
Analysts at Field Effect noted in a report shared with Cyber Security News (CSN) that this campaign signifies a strategic shift for Star Blizzard. The group is moving away from direct spear-phishing tactics towards broader initial-contact campaigns. This new approach enables the attackers to first identify and engage with recipients who show a willingness to interact before deploying any malicious payloads. Field Effect said in a report that compromised websites are being utilized to register accounts for distributing these phishing emails.
This adaptation underscores the group’s history of continuously refining its attack methodologies, which previously included malicious WhatsApp QR-code attacks targeting high-value individuals.
Russian Hackers Target 100+ Organizations
The initial phase of the RedFlick attack is characterized by an email devoid of any attachments, malware, or exploits. Instead, these messages are crafted to initiate a dialogue, often mimicking legitimate professional correspondence such as invitations, policy discussions, financial inquiries, research collaboration requests, or document sharing. The objective is to elicit a reply, which signals the recipient’s trust in the sender and opens the door to the subsequent, more malicious stages of the attack.
Upon receiving a reply, the attackers send a follow-up email containing a password-protected RAR or ZIP archive. Crucially, the password for this archive is embedded as an image within the email itself. This tactic serves a dual purpose: it hinders automated security solutions from inspecting the archive’s contents and lends an air of legitimacy to the attachment, as it arrives within an ongoing, seemingly normal conversation. This method of using password-protected archives to bypass email scanning is a known technique for reducing visibility to security products.
Once opened, these archives may contain either a VHDX virtual disk image or a Windows shortcut (LNK file) cleverly disguised as a PDF document. These files, when executed, trigger scripts and leverage legitimate Windows utilities to download additional malicious components from infrastructure controlled by the attackers. This technique of concealing harmful actions behind a decoy document-like shortcut is reminiscent of earlier weaponized PDF and LNK attacks.
Beginning in April, the RedFlick installers were observed performing several critical actions. They established scheduled tasks for persistence, gathered basic system information, enabled WebDAV access, and retrieved the necessary files to install the CosmicPulse backdoor. Scheduled tasks provide attackers with a reliable mechanism to re-execute code, while WebDAV is a standard Windows protocol for accessing remote files, further aiding in lateral movement and data exfiltration.
By July, the attackers had introduced an additional layer of obfuscation. They began nesting a password-protected RAR archive inside a ZIP file. The shortcut within this nested archive would then download a PDF containing encoded data. PowerShell was subsequently used to extract and execute this data, leading to the installation of an MSI installer. This multi-layered approach further distances the visible, benign-looking document from the underlying malicious processes, making detection even more challenging.
What You Should Do
- Scrutinize Email Threads: Be vigilant for encrypted RAR or ZIP archives that arrive following initial emails devoid of attachments, particularly if the sender claims an attachment was omitted or provides a password within the conversation.
- Isolate and Review Encrypted Archives: Where operational policies permit, implement enhanced review procedures for encrypted archives that cannot be automatically inspected before they reach end-user endpoints.
- Monitor for Suspicious Activity Chains: Correlate events such as archive extraction, VHDX mounting, LNK file execution, MSI installer activity, PowerShell commands, WebDAV connections, scheduled task creation, and unusual external network connections.
- Verify Unexpected Requests: Always independently verify unexpected requests or attachments via a known, alternative communication channel (e.g., a phone call) before interacting with them, especially for organizations involved in Ukraine-related policy, research, diplomacy, journalism, or finance.
- Incident Response Protocol: If an execution is suspected, immediately isolate the affected device, preserve the entire email thread and the original archive, and thoroughly inspect scheduled tasks and other persistence mechanisms.
- Forensic Analysis: Review process and network logs to identify the infection vector and propagation path. Additionally, examine the compromised user’s accounts, active sessions, mailbox rules, and recent messages for signs of further targeting or compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.