OCTOBER 1, 2026
Subscribe
Global Press Media · World Report
Technology

Kremlin-Linked Russian Hackers Expand RedFlick Phishing Attack to Over 100 Companies

Kremlin-Linked Russian Hackers Expand RedFlick Phishing Attack to Over 100 Companies

Cybersecurity analysts who initially uncovered the activity say Russian hackers purportedly connected to the Kremlin have widened a phishing operation now aimed at over a hundred entities. Named “RedFlick,” the scheme swaps the usual malicious attachment for a seemingly harmless email thread, rendering the bait more difficult to detect.

The RedFlick delivery starts with an email thread that appears legitimate and mirrors everyday business communication. Rather than attaching a dubious file, the note includes a link or brief excerpt that, once clicked, sends the recipient to a hijacked website delivering the payload. By nesting the malicious code inside a familiar conversation, the perpetrators seek to evade both user doubt and automated filters that would flag conspicuous attachments.

Investigators note that the operation touches a wide array of industries, ranging from financial services and tech companies to government contractors and health‑care providers. Although the precise roster of targets is not disclosed, the scope indicates the actors are after extensive intelligence collection or credential theft rather than a tightly scoped espionage mission.

Experts in security point to this change as evidence of rising sophistication among state‑linked threat groups. Conventional phishing messages typically depend on obvious cues—like typographical errors or conspicuous malware‑laden attachments—that alert alert users or email gateways. By inserting the malicious component into a credible exchange, RedFlick lowers detection odds and boosts the probability that recipients will interact with it.

A cybersecurity news site first reported the campaign, observing that the novel delivery swaps “an obvious malicious attachment with a conversation that looks like ordinary professional correspondence.” Follow‑up examinations by independent security firms validated the tactic and linked the underlying infrastructure to servers previously associated with Russian‑state‑sponsored groups.

Defenders counsel firms to tighten basic hygiene practices: confirm unsolicited requests via separate channels, deploy strong email authentication schemes like DMARC, and mandate multi‑factor authentication for privileged accounts. They also recommend endpoint detection and response solutions capable of flagging anomalous activity after a link is activated.

Law‑enforcement and intelligence bodies are said to be tracking the RedFlick campaign, even as attribution stays a complicated task that demands matching technical data with geopolitical context. Analysts anticipate the perpetrators will refine the method, possibly layering further obfuscation or aiming at supply‑chain partners to heighten effect.

With phishing tactics constantly advancing, the RedFlick case highlights the need for ongoing user training and flexible security controls. Companies that view email as a primary defense rather than a peripheral issue will be better equipped to curb the danger presented by ever‑more covert campaigns.

Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related