RedFlick Gives Star Blizzard a Shorter Route From Phishing to Persistence
An email thread can make an unexpected attachment feel expected. Microsoft Threat Intelligence reports that Star Blizzard used larger phishing campaigns and RedFlick malware delivery during 2026. It observed at least 13 campaigns and activity affecting more than 100 organisations, mainly in the US and UK. That is reach, not confirmed infections. Targets include Ukraine and organisations supporting it.
The first message usually has no attachment. A follow-up after a response may carry a password-protected RAR or ZIP archive. Some messages came from accounts on compromised websites. Observed chains include shortcuts, installers, WebDAV and scheduled tasks leading to the CosmicPulse backdoor. RedFlick requires less user interaction than earlier ClickFix activity. Microsoft does not describe a zero-day, and a reply alone does not execute malware.
Decide where the investigation begins
BlackTree analysis: Treat the reply as a branching point in the investigation, not as proof of infection. One recipient may have read and answered the initial lure. Another may have received the archive. A third may have opened a shortcut inside it. Those are different exposure levels and need different evidence. Build a recipient list from the original campaign mail, then trace reply chains and follow-up attachments before opening an endpoint incident for everyone on the list.
The sender check also needs to happen outside the thread. A plausible display name or a real domain can still be part of this campaign if the account sits on a compromised site. Check the registered domain and the relationship to the named organisation. For a sensitive invitation or document, use an address or phone number already held by the recipient, not one supplied by the unexpected email. This is a practical stop point before the archive reaches the endpoint.
Follow execution, not just message delivery
When an archive was opened, retain the original mail, headers, attachment and endpoint timeline. Look for a shortcut or virtual disk launched from the extracted material, subsequent installer activity, newly registered scheduled tasks and network access to remote resources. Correlate those events by host and time. An ordinary-looking task name is weak evidence on its own; a new task created after the archive opened and reaching an unrecognised remote path is much stronger. Microsoft’s report includes detections, hunting queries and indicators that can refine this search without treating one file name as universal across all variants.
BlackTree analysis: Separate containment decisions by evidence. For a delivered but unopened message, remove related mail and brief the targeted team. For an executed attachment or suspicious task chain, isolate the host while preserving the task definitions, process history and network records. Then scope other recipients and endpoints that received the same follow-up. Closing the mail case because a download was blocked can miss a task or backdoor installed earlier in the chain.
The organisation should rehearse this workflow with the teams most likely to receive policy, conference or financial invitations. Give them a way to report a credible-looking thread without first extracting its archive. Combine that with phishing-resistant authentication, mail scanning and endpoint monitoring, as Microsoft recommends. Those controls serve different stages; the investigation still has to establish which stage each recipient reached.
BlackTree’s earlier Custom GPT ClickFix report covers a separate campaign where a user pasted a command. In this case, defenders should focus on the attachment-to-task handoff. The comparison helps frame the evidence required, without implying the campaigns share infrastructure or victims.
Source
- Microsoft Threat Intelligence, Star Blizzard refines phishing and malware delivery with the RedFlick technique, published 29 September 2026, no publication time shown; reviewed 30 September 2026.


