Star Blizzard RedFlick: Reply-thread phishing delivering password-protected archive with image-embedded password

Detects a multi-stage phishing pattern attributed to Star Blizzard (also known as Callisto Group or COLDRIVER). The attack involves an initial email containing no attachments to establish trust or initiate a thread, followed by a subsequent reply-thread email containing both an archive file (ZIP/RAR) and an image file. This technique is designed to bypass email security scanners by hiding the archive password within the image attachment or obscuring the malicious payload context.