Star Blizzard Uses Fake Event Invitations to Deliver CosmicPulse Backdoor

Russian state-linked threat actor Star Blizzard has launched a series of phishing campaigns using fake event invitations to target people and organizations connected to Ukraine, according to Microsoft.

The campaigns have affected more than 100 organizations since January 2026, primarily in the United States and United Kingdom. Microsoft confirmed at least one infected computer, although it did not disclose the total number of compromised organizations.

Star Blizzard has been associated with Center 18 of Russia's Federal Security Service (FSB) by security agencies from the United States, United Kingdom, Australia, Canada, and New Zealand.

The group has historically targeted victims with spear-phishing emails designed to steal credentials. More recently, it has developed new techniques for delivering malware.

Fake Invitations Used as Phishing Lures

Microsoft identified at least 13 larger campaigns during 2026, each involving tens to hundreds of emails in addition to the group's regular targeted phishing operations.

The campaigns use fake invitations that appear to come from well-known think tanks and nongovernmental organizations, including:

  • Chatham House
  • Atlantic Council
  • Ukrainian government organizations

Many messages are crafted to appear as though they were sent from inside the targeted organization.

The initial email generally contains no attachment.

If the recipient responds, Star Blizzard sends a password-protected RAR or ZIP archive. The password is typically provided inside an image accompanying the message.

The first campaigns observed in January and February impersonated Ukrainian authorities and delivered fake tax audit and fine notices to users of the Ukrainian email service Ukr.net.

Later campaigns used different themes, including:

  • A fake water shutdown notification targeting hotels in Kyiv
  • A fake payment notification sent to employees of an international financial organization
  • Fake invitations to Ukraine-related conferences and events

A March campaign involving an Atlantic Council-themed invitation used a different delivery method.

Microsoft said recipients who responded to that campaign were directed toward DarkSword, an iPhone exploit kit, instead of the Windows malware used in other campaigns.

From ClickFix to RedFlick

In 2025, Star Blizzard used ClickFix-style fake CAPTCHA pages that attempted to persuade victims to manually execute malicious commands.

In 2026, Microsoft observed the group using a different technique called RedFlick.

RedFlick relies on Windows scheduled tasks to establish persistence and deploy a Python-based backdoor called CosmicPulse.

The infection chain typically begins with a malicious Windows shortcut file disguised as a PDF.

How the Malware Is Installed

Microsoft identified several versions of the infection chain.

The common components include:

  1. A malicious LNK file disguised as a PDF
  2. Commands that download an MSI installer
  3. Windows scheduled tasks
  4. A downloader disguised as a legitimate Control Panel component
  5. The CosmicPulse Python backdoor

In one January campaign, the hidden script used the Windows SSH client to download the installer.

In a July campaign, the LNK file downloaded a PDF containing a hidden command designed to retrieve the installer.

Malicious Scheduled Tasks

In an April campaign, the MSI installer created three scheduled tasks designed to look like legitimate Windows networking or system components:

Internet Quality Test Connection
Network Configuration Manager
System Health Monitor

Each task performed a different function.

Internet Quality Test Connection

This task sends the computer name and username to the attacker's command-and-control server and can execute additional code retrieved from the remote infrastructure.

Network Configuration Manager

This task establishes WebDAV, allowing a remote web address to be accessed as though it were a local folder.

System Health Monitor

This task uses control.exe, the Windows Control Panel executable, to execute the next stage retrieved from the command-and-control infrastructure.

CosmicPulse Backdoor

The next stage is a downloader disguised as a Control Panel component.

It ultimately installs CosmicPulse, a Python-based backdoor that provides attackers with continued access to the compromised system.

Earlier reporting referred to the downloader as NOROBOT or BAITSWITCH.

The combination of scheduled tasks and a remote downloader allows the threat actor to maintain persistence while disguising malicious components as legitimate Windows functionality.

Star Blizzard Uses Compromised Websites

Since March, Microsoft has observed Star Blizzard sending phishing messages from email accounts hosted on WordPress and cPanel websites.

Microsoft said it is highly confident that the group compromised these websites to obtain the accounts.

Previously, Star Blizzard primarily relied on free email services, including Proton and Microsoft consumer accounts.

This change gives the phishing emails additional legitimacy because the sender addresses can appear to originate from compromised infrastructure rather than disposable email accounts.

Possible Overlap With Ukrainian Campaign

Microsoft said the techniques overlap with a June campaign documented by the Digital Security Lab Ukraine that targeted Ukrainian civil society organizations using fake Ukraine Recovery Conference invitations.

That campaign did not identify the responsible threat actor and researchers were unable to recover the final payload.

Two indicators appeared in both sets of reporting:

103.160.59[.]97
secure-dns-hub[.]com

However, the shared indicators alone do not establish that the same threat actor conducted both campaigns.

Microsoft said secure-dns-hub[.]com was still being used when its report was published on September 29, 2026.

Defensive Recommendations

Organizations likely to be targeted by Star Blizzard should review email, endpoint, and network telemetry for the indicators associated with the campaign.

Microsoft recommends:

  • Carefully inspect sender addresses, especially when the organization name appears only before the @ symbol.
  • Verify suspicious invitations through a known phone number or trusted email address.
  • Search for the three scheduled task names associated with the RedFlick campaigns.
  • Hunt for Microsoft Defender detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
  • Extend Microsoft Defender XDR hunting queries beyond their default seven-day search window when historical telemetry is available.
  • Retain longer-term logs in platforms such as Microsoft Sentinel when historical investigation is required.
  • Restrict unnecessary outbound SSH connections.
  • Enable attack surface reduction rules that block rare, new, or untrusted executable files and obfuscated scripts.
  • Use phishing-resistant authentication methods.
  • Monitor for credential and session-cookie theft associated with adversary-in-the-middle phishing tools.

For organizations using iPhones, Trellix recommends updating devices to iOS 26.3 or later, which addresses the vulnerabilities used by DarkSword, and enabling Lockdown Mode where appropriate.

Key Takeaway

Star Blizzard continues to evolve its phishing and malware delivery techniques.

The group's latest campaigns combine social engineering, compromised email infrastructure, malicious archives, LNK files, scheduled tasks, WebDAV, and the CosmicPulse backdoor to establish persistent access.

The shift from ClickFix-style lures to RedFlick also shows how the group continues to change its delivery methods while maintaining the same broader objective of compromising organizations connected to Ukraine.