CyberPeople

Star Blizzard: How Russian FSB Hackers Infect Computers via Fake Invites

Star Blizzard: Fake Invites Spread a Backdoor

Russian Star Blizzard (FSB) hackers spread the CosmicPulse backdoor through fake conference invites. How the RedFlick technique works and how to defend.

On September 29, 2026, the Microsoft Threat Intelligence team published a report detailing how the Russian state-sponsored group Star Blizzard changed its tactics throughout 2026, moving from targeted phishing to large-scale campaigns delivering malware through a new technique Microsoft calls RedFlick. The main lure is fake invitations to closed conferences and roundtables. According to Microsoft, since January 2026 the group has run at least 13 separate large campaigns affecting over 100 organizations, mostly in the US and UK — but the first strikes were aimed precisely at Ukraine.

Who Star Blizzard is and why it concerns Ukraine

Star Blizzard is not a new name. Back in December 2023, cybersecurity agencies of the US, UK, Australia, Canada, and New Zealand stated in a joint advisory that this group is "almost certainly" subordinated to Center 18 of Russia's Federal Security Service (FSB). CISA officially attributes Star Blizzard to that structure.

Historically, the group specialized in cyber espionage: it stole email passwords by impersonating the target's acquaintances, and since 2023 it has actively used fake conference and event invitations as bait. Over the years its victims have included politicians, journalists, academics, human-rights defenders, and civic activists. The group has appeared in reports under various names — including ColdRiver, Callisto Group, and Seaborgium — but it is the same attacker with a stable signature: patient, multi-stage phishing disguised as ordinary business correspondence. For the Ukrainian audience this is not an abstract threat but a very concrete one: the first 2026 campaigns, recorded in January and February, were aimed precisely at Ukraine.

Then the attackers impersonated Ukrainian state bodies and sent users of the Ukrainian mail service Ukr.net messages about tax audits or unpaid fines. Microsoft believes Star Blizzard may have used these first campaigns as a proving ground to test new tools before expanding attacks on Western organizations.

From targeted phishing to mass campaigns

The main 2026 change is the shift from purely targeted spear-phishing to larger operations. According to Microsoft, Star Blizzard began sending campaigns of tens to hundreds of emails each — something not previously observed for this group. This points to the use of a mass-mailing platform that automates campaign execution and expands the initial pool of targets.

The infrastructure changed too. Starting in March 2026, the group sent emails from accounts on hacked WordPress and cPanel sites — Microsoft believes with high confidence these sites were compromised precisely for this purpose. Previously the group mostly used free mail services, including Proton and consumer Microsoft accounts.

The expansion of targets is also telling: while the first attacks focused on Ukraine, from March the group attacks non-governmental organizations, think tanks, governments, and financial institutions worldwide — especially those politically or financially supporting Ukraine. Microsoft also recorded attacks on several employees of the same organization, with emails often crafted to look like they came from inside the organization itself.

Phishing email and hacker

RedFlick: a new malware-delivery technique

The most notable innovation is the delivery technique Microsoft tracks as RedFlick. Its essence is to trigger a set of Windows scheduled tasks that deploy the group's signature backdoor — CosmicPulse. The main difference from the previous approach, which used ClickFix chains: if previously the victim had to perform several actions, RedFlick requires only a single user interaction. This substantially lowers the compromise threshold.

The infection scheme looks like this:

  1. The first email has no attachment. It contains only an invitation and a request to reply. No malicious file is in the first email — so it passes email security filters more easily.
  2. The victim's reply. If the person replies, the attackers send a follow-up email with a password-protected RAR or ZIP archive.
  3. The password is in an image. The archive password is delivered as an image in the email body, complicating automatic detection.
  4. The archive contents. In different campaigns these were virtual hard disk (VHDX) files or Windows shortcuts (LNK) disguised as PDF documents.
  5. Chain launch. The shortcuts run scripts and legitimate Windows utilities that download additional components from the attackers' infrastructure.
  6. MSI and scheduled tasks. The MSI installer creates scheduled tasks that download and execute the CosmicPulse loader, disguised as a Control Panel applet (CPL), via control.exe.

From April 2026, RedFlick installers created scheduled tasks that gathered basic host information, enabled WebDAV access, and pulled components to install the backdoor. In July the group added another layer of disguise: the password-protected RAR archive was placed inside a ZIP file, and the nested shortcut downloaded a PDF with encoded data that PowerShell extracted and executed to obtain the MSI installer.

CosmicPulse: what this backdoor is

The final payload is CosmicPulse, a Python backdoor. It gives the attackers persistent remote access to a compromised Windows machine. This loader previously appeared in other researchers' reports under the names NOROBOT or BAITSWITCH — mentioned, among others, by Zscaler and Google Threat Intelligence analysts in the context of ColdRiver (Star Blizzard's previous name) attacks.

The backdoor's goal is not extortion but long-term espionage: stealing correspondence, credentials, documents, and other confidential information from organizations working on sensitive foreign-policy and security topics. The choice of Python for the backdoor is telling: such tools are easier to modify and port between systems, and the code is easier to hide among legitimate scripts. Additional flexibility comes from using built-in Windows mechanisms — scheduled tasks, Control Panel applets, and WebDAV — which rarely raise suspicion in monitoring systems compared to exotic malware. Notably, Microsoft confirmed at least one case where RedFlick contacted remote infrastructure, created scheduled tasks, and deployed CosmicPulse, establishing persistent access to the affected endpoint.

Social engineering: fake invites and other lures

The main social-engineering technique is invitations to exclusive events, supposedly organized by well-known think tanks or non-governmental organizations. Microsoft cites Chatham House and the Atlantic Council as examples. Some emails are crafted to look like they came from colleagues inside the victim's organization.

Besides invitations, other lures were used in different campaigns: tax-audit and fine notices (for Ukr.net users), water-outage notices in Kyiv hotels, and payment notices for staff of an international financial organization.

An important detail for the Ukrainian community: Microsoft notes these campaigns' techniques overlap with a June operation documented by Ukraine's Digital Security Lab. That campaign used fake invitations to the Ukraine Recovery Conference and targeted Ukrainian civic organizations. The Hacker News' comparison found two shared indicators in both reports: IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com.

Malware backdoor infection

DarkSword and Evilginx: iPhone attacks and 2FA bypass

A separate line of Star Blizzard attacks targets iPhone owners. Microsoft reported that some people who replied to an invitation styled as coming from the Atlantic Council received, instead of a Windows backdoor, a link to DarkSword — an iPhone vulnerability-exploitation kit. Trellix researchers found four such emails sent on March 26. Per Trellix's advice, users should update iPhones to iOS 26.3 or newer, which closes all six vulnerabilities DarkSword exploits, and, where updating isn't yet possible, enable Lockdown Mode.

In addition, the group continues password-stealing phishing campaigns via the Evilginx tool. Its danger lies in intercepting not only passwords but also session cookies — bypassing two-factor authentication if it's built only on one-time codes.

How to protect yourself: practical tips

Microsoft addresses its recommendations primarily to government bodies, non-governmental organizations, and think tanks working on Ukraine-related topics or supporting Ukraine. But most of the advice is useful for any organization:

  1. Verify invitations through a separate channel. Before replying to an event invitation or opening an archive, contact the organizer directly via the official site or a known contact — not by replying to the email itself.
  2. Be wary of archives with a password in an image. A password-protected RAR/ZIP whose password was sent as an image is a classic sign of this campaign.
  3. Look for signs of compromise. Check for suspicious Windows scheduled tasks and antivirus detections by the signatures Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
  4. Enable automated response. Set up fully automated investigation and threat remediation so endpoint protection responds to incidents immediately.
  5. Update iPhones. Install iOS 26.3 or newer, and for higher-risk groups enable Lockdown Mode.
  6. Use phishing-resistant authentication. Since Evilginx intercepts cookies and 2FA codes, prefer hardware keys (FIDO2/Passkey), which resist such interception.
  7. Check credentials for breaches. If employees' passwords may have already leaked, use our free data-breach check tool.
  8. Widen your threat-hunting horizon. Microsoft published ready hunting queries and indicators of compromise for these campaigns. Default queries cover only 7 days of history, so to detect these attacks you should extend them several months back — the campaigns run for months.
  9. Train your team. This attack starts with a person replying to a "normal" email. Basic cyber-hygiene skills are the cheapest defense. Our material on learning cybersecurity from scratch will help deepen this knowledge.
Cyber espionage and email security

Conclusion

Star Blizzard shows how a state espionage group methodically refines its tools: mass mailings instead of targeted phishing, hacked sites as mail infrastructure, the single-step RedFlick scheme instead of multi-step ClickFix, and the Python CosmicPulse backdoor. But the group's strongest weapon is not technology — it's social engineering: conference invitations styled as coming from well-known organizations, which are hard to disbelieve.

For Ukrainian organizations, civic initiatives, and everyone working on national-security topics, the main conclusion is simple: any unexpected event invitation or "urgent" message from a state body should be verified through an independent channel before replying. That single second of caution breaks the whole RedFlick chain before it even starts.

Stay ahead of threats

Weekly cybersecurity intelligence in your inbox. No spam.

CyberPeople contributor