HomeSecurityStar Blizzard uses fake invitations to install Windows backdoor

Star Blizzard uses fake invitations to install Windows backdoor

The Star Blizzard cyberespionage group , which is linked to Russian intelligence services , has launched new phishing campaigns, using fake conference and event invitations to install malware on Windows computers . According to Microsoft, the attacks are aimed at misleading users and organizations associated with Ukraine , while the activity has spread mainly to the United States and the United Kingdom.

Star Blizzard uses fake invitations to install Windows backdoor

Since January, Microsoft has documented more than 100 organizations affected by these campaigns. While at least one computer infection, the exact number of organizations that the attackers managed to gain access to has not been made public. This activity highlights the risks that arise when attackers exploit trust in business communications and use messages that appear completely legitimate.

Who is the Star Blizzard team?

Star Blizzard is also known by other names, such as Callisto Group and ColdRiver, and has been linked to cyberespionage attributed to Russian state actors. In December 2023, intelligence and cybersecurity agencies from the United States, the United Kingdom, Australia, Canada, and New Zealand assessed that the group operates under the supervision of Center 18 of Russia's Federal Security Service (FSB).

The group has a long history of phishing, in which attackers impersonate individuals or organizations known to their victims. The primary goal is to steal email credentials, which can be exploited to access confidential information, correspondence, and corporate systems.

As early as 2023, Star Blizzard used invitations to conferences and professional events as bait. Often, this was preceded by an exchange of messages with the target to establish a relationship of trust before sending the malicious link or file.

RedFlick: The new CosmicPulse installation method

Microsoft identified at least 13 significant campaigns by the group in 2026, each involving dozens or hundreds of emails. These attacks are in addition to Star Blizzard's usual activity targeted phishing

See also: Russian Star Blizzard hackers target WhatsApp accounts

Since March, the attackers have reportedly been using compromised email on websites hosted via WordPress and cPanel. This change differentiates their tactics from previous operations, in which they relied more on free email services such as Proton, as well as Microsoft accounts for individuals.

The latest technique, which Microsoft calls RedFlick, relies on the use of Windows Scheduled Tasks, which allow actions to be automatically executed at specified intervals or under specific conditions. This process installs CosmicPulse, a Python-based backdoor.

CosmicPulse can allow attackers to maintain access to an infected computer and perform additional actions via remote commands. This creates the risk of further compromise, depending on the user's permissions and the features enabled during the attack.

How the fake invitation trap works

The messages often appear as invitations from well-known think tanks and organizations, such as Chatham House and the Atlantic Council, or as communications that appear to come from the recipient's own organization.

In many cases, the first email does not contain any attached file. Instead, it invites the recipient to respond or confirm their participation. Only after the response is sent is a ZIP or RAR file . The password is displayed in an image, a choice that can make some automated security checks difficult.

The content of the messages is tailored to the target. In January and February, the perpetrators posed as Ukrainian authorities and sent fake notifications of tax audits and fines to users of the Ukr.net email service. In other cases, the baits involved potential water outages in Kiev hotels or payment notifications to employees of an international financial institution.

Choosing topics related to work, financial obligations, or professional events increases the likelihood that a message will be perceived as urgent and credible.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

AmnesiaStealer macOS malware ClickFix attack data theft

From the LNK file to the installation of malware

Microsoft has identified different variants of the infection chain, which share some common characteristics. The process usually begins with a Windows shortcut file (LNK), which is disguised as a PDF document.

When the user opens the shortcut, commands are executed in the background that attempt to download an installer from a remote server. In a January sample, a hidden script that leveraged SSH to download the file. In another variant, in July, the shortcut downloaded a PDF that contained a hidden command to retrieve the installer.

In an April sample, the Windows Installer (MSI) package created three scheduled tasks with names that refer to normal system operations:

  • Internet Quality Test Connection
  • Network Configuration Manager
  • System Health Monitor

These tasks take on different roles, such as passing the computer name and user to the command and control (C2) server, configuring WebDAV, and executing subsequent stages of the attack via control.exe.

A downloader disguised as a Control Panel item then installs CosmicPulse. This downloader has been reported in previous analyses under the names NOROBOT and BAITSWITCH.

The use of names that resemble legitimate Windows functions can make a superficial scan difficult, especially in corporate environments with a large number of computers. However, the presence of these names alone is not definitive evidence of infection and should be considered in conjunction with other findings.

Link to attacks against Ukraine and possible DarkSword

Researchers have identified similarities between Star Blizzard's techniques and a June campaign documented by Digital Security Lab Ukraine. That operation targeted Ukrainian civil society organizations and used fake invitations to the Ukraine Restoration Conference.

The lab report did not attribute the attack to a specific group, and the final malicious payload could not be recovered. According to The Hacker News, common elements included the IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com. This evidence reinforces the need for further investigation, but does not in itself prove that the two operations were carried out by the same perpetrators.

Meanwhile, in March, a different case was reported: people who responded to an invitation purportedly from the Atlantic Councilreceived a link related to DarkSword, an iPhone exploit kit (rather than the Windows backdoor). Proofpoint reported similar messages, while Trellix detected four messages on March 26. However, Trellix described the level of certainty that they were connected to DarkSword as moderate, as the relevant pages were no longer available and no exploit code was recovered.

See also: Star Blizzard: Russian hacking group launches global spear-phishing attack

The incident shows that the same social engineering techniques can be used to target different platforms, depending on the purpose of the campaign.

How organizations and users can protect themselves

Microsoft has published breach indicators and threat intelligence queries to identify related activity. Organizations working with Ukrainian actors, NGOs, government agencies , and think tanks should pay particular attention to the following measures:

  • Verify the sender: Check the entire email address, not just the display name. If an invitation is unexpected, contact the purported organizer using contact information you've already confirmed.
  • Check attachments: Be wary of password-protected ZIP or RAR files, especially when they contain shortcuts or request actions to view a document.
  • Search for suspicious tasks: Security teams can check for the three scheduled task names, as well as Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse in Microsoft Defender.
  • Expanding the controls: Microsoft Defender XDR’s default search queries may only cover seven days. Administrators should adjust the time frame and leverage available historical logs, as Advanced Hunting raw data is retained for a limited period, up to 30 days according to Microsoft’s information.
  • Restrict unnecessary SSH connections: Outbound SSH traffic should only be allowed where required for legitimate business needs.
  • Enable security rules: Attack Surface Reduction rules can restrict the execution of suspicious or untrusted files and cloaked scripts.
HOOKEDGE backdoor APT28 attack on European governments

Additionally, Star Blizzard continues to use phishing techniques to steal credentials. Tools like Evilginx can interfere with the login process and steal session cookies, in some cases bypassing two-factor authentication protection. For this reason, organizations should consider using phishing-resistant authentication methods such as passkeys or FIDO2 security certificates.

See also: World of Warcraft Forever: Blizzard's new Classic+ causes havoc before it even launches

For iPhones, Trellix recommended installing iOS 26.3 or later, which it said fixes the six vulnerabilities exploited by DarkSword. Where an update is not yet available, it is recommended to consider Lockdown Mode, depending on the needs and compatibility of the device.

Early detection remains critical

Microsoft's public report does not include detailed cleanup steps for every possible variant of the infection. Therefore, if suspicious tasks, related files, or evidence of communication with known attack infrastructure, organizations should follow their incident response procedures and consult Microsoft Defender XDR threat analysis reports.

The Star Blizzard case highlights that phishing is no longer based solely on crude messages with obvious errors. Attackers are investing in creating convincing business scenarios, compromising accounts, and using legitimate operating system features to remain undetected.

For businesses, effective defense requires a combination of technical controls, multifactor protection , ongoing monitoring, and employee education. Confirming an invitation before opening an attachment can prevent initial infection, while maintaining logs and promptly investigating suspicious activity can limit the consequences of a breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS