Star Blizzard RedFlick: Reply-thread phishing delivering password-protected archive with image-embedded password
Detects a multi-stage phishing pattern attributed to Star Blizzard (also known as Callisto Group or COLDRIVER). The attack involves an initial email containing no attachments to establish trust or initiate a thread, followed by a subsequent reply-thread email containing both an archive file (ZIP/RAR) and an image file. This technique is designed to bypass email security scanners by hiding the archive password within the image attachment or obscuring the malicious payload context.
Microsoft Sentinel (KQL)

