Blog Main Image
October 1, 2026

The Email That Waits For Your Reply

The first email in this campaign contains nothing harmful. No attachment, no payload, no obviously dodgy link. It is an invitation to a closed-door policy roundtable, written to look as though it came from a respected think tank. Only if the recipient writes back does the second email arrive, and that is the one carrying the file.

Microsoft Threat Intelligence published its analysis on 29 September 2026. It describes how the Russian state-linked group it tracks as Star Blizzard has changed how it delivers malware, and it contains a lesson that applies well beyond the diplomats and researchers being targeted.

What did Microsoft actually find?

Microsoft observed at least 13 large-scale phishing campaigns between January and August 2026, each ranging from tens to hundreds of messages. In total the activity reached more than 100 organisations, mainly in the United States and the United Kingdom. Targets included Ukrainian individuals and institutions, international NGOs, think tanks, governments and financial institutions supporting Ukraine.

Microsoft notes that the group is attributed by the US Cybersecurity and Infrastructure Security Agency (CISA) as subordinate to the Russian Federal Security Service (FSB) Centre 18. Star Blizzard has been the subject of a joint government advisory before, so none of this is new in terms of who is behind it. What has changed is the delivery method.

Earlier activity from the group relied on ClickFix-style infection chains. Microsoft describes the newer technique, which it calls RedFlick, as a notable departure from that. It is built around scheduled tasks and a reply-gated email exchange.

How does the reply-gated attack work?

The chain runs in a particular order, and the order is the point.

First, a phishing email arrives with a subject line impersonating a legitimate organisation. Microsoft gives examples such as an invitation to a private roundtable at a well-known policy institute. There is no malicious attachment at this stage.

Second, if the recipient responds, the attacker sends a follow-up carrying a password-protected RAR or ZIP archive. The password is embedded in the email as an image rather than as text.

Third, the archive holds a shortcut (LNK) file disguised as a PDF. Opening it starts a chain of commands that varies by campaign. Microsoft describes one variant that runs a batch script and uses SSH to fetch an installer, and another that uses curl to download a PDF, pulls an encoded payload out of it with PowerShell, and then retrieves an MSI installer.

Fourth, the installer creates scheduled tasks with names designed to look like ordinary Windows housekeeping, such as "Internet Quality Test Connection", "Network Configuration Manager" and "System Health Monitor". These tasks beacon device details to the attacker's server and run a downloader that Microsoft names CosmicPulse, which in turn installs a backdoor.

Sequence diagram showing the reply-gated RedFlick chain between the attacker and the recipient, and what there is to scan at each step

Why does a reply-gated email work so well?

There are two separate effects, and they reinforce each other.

The first is technical. A first message with no attachment and no payload gives automated filtering very little to examine. Microsoft does not claim the first email is invisible to its tooling, and it recommends Safe Links, Safe Attachments and zero-hour auto purge. But the structure means the dangerous content only appears after a human has already engaged, and by then the exchange looks like a normal two-way conversation.

The second is psychological, and it is the one worth dwelling on. Once you have replied to someone, you have made a small commitment. The next message from them is no longer an unsolicited email from a stranger. It is the answer to your question. Most people extend more trust to a reply they asked for than to a message they did not. Attackers know this, and it is why the second email carries the weight.

The password-in-an-image detail looks deliberate too. Microsoft does not explain the reasoning, so this is our reading: a password that is not plain text is harder for a simple rule to lift out, and it feels like a careful sender taking a sensible precaution.

What should organisations do about it?

Microsoft's own recommendations are mostly about layers that sit outside the inbox. Those that stood out in the write-up:

  • Use phishing-resistant authentication and Conditional Access, and investigate unusual sign-in attempts.
  • Turn on Safe Links, Safe Attachments and zero-hour auto purge in Microsoft Defender for Office 365.
  • Run endpoint detection in block mode, with attack surface reduction rules that stop executables running unless they meet prevalence, age or trusted-list criteria.
  • Prevent outbound SSH connections to external networks where there is no business need for them.
  • Hunt for the three scheduled task names above. Microsoft provides advanced hunting queries for Defender XDR customers.

None of that depends on a person making a perfect call at the right moment, which is how it should be. But the human layer still matters, because the whole chain needs somebody to reply and then open a file. Equipping people to notice that moment is a sensible part of the defence.

What can people do at the reply step?

The useful habit is to treat the second message as seriously as the first. A few practical checks help:

  • Verify an invitation to a closed event through a channel you already trust, such as the organiser's published contact details, before replying.
  • Be wary of any follow-up that asks you to open a password-protected archive, especially when the password arrives in an unusual form.
  • Check what a file really is. A "PDF" that is actually a shortcut will show a different file type once you enable file extensions in Windows.
  • Report it to your security team rather than deleting it quietly. A reported message gives defenders the chance to look for the same email in other inboxes.

For teams, it helps to rehearse this exact pattern in awareness exercises. Many simulations stop at the first click on the first email. A reply-gated scenario tests whether people stay careful once a conversation has started, which is the point where trust tends to rise.

The bottom line

RedFlick is a targeted espionage campaign, and most readers will never be on Star Blizzard's list. The technique is not exclusive to it, though. Any attacker can hold the payload back until a human has replied, and the reply makes the next message feel safer than it is. Defence works best when technical controls assume the second email will get through, and people are comfortable pausing at the point where a conversation feels most natural.

Source: Microsoft Threat Intelligence, 29 September 2026. Attribution context: CISA advisory AA23-341A.

Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.

Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Scroll To Top Arrow