Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ethereum Gets Another Privacy Boost as Aztec Brings Back zk.money

    September 30, 2026

    NASA Opens 2027 Human Lander Challenge for Lunar Communications

    September 30, 2026

    China Brief: Was Xi’s Meeting With Trump a Bust?

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ethereum Gets Another Privacy Boost as Aztec Brings Back zk.money
    • NASA Opens 2027 Human Lander Challenge for Lunar Communications
    • China Brief: Was Xi’s Meeting With Trump a Bust?
    • News live: Alan Kohler announces retirement from ABC after 31 years; six Australian universities in top 100 global rankings | Australia news
    • England v Czech Republic: Czechs prepare for Wembley 30 years after Euro ’96
    • Is ChatGPT your new Google Workspace alternative? Meet Space, Pages, and slides
    • Russia’s Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
    • Hut 8 locks in $1B credit line, but faces 40% liquidity rules
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Russia’s Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.

    The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been disclosed.

    Security agencies in the U.S., U.K., Australia, Canada and New Zealand said in December 2023 that Star Blizzard almost certainly works under Center 18 of Russia’s Federal Security Service (FSB). The group has long stolen email passwords by posing as people its targets know.

    By 2023, it had already used fake conference and event invitations as bait, often exchanging messages with a target before sending a malicious link.

    Microsoft counted at least 13 larger campaigns this year, each with tens to hundreds of emails, on top of the group’s usual targeted phishing.

    Since March, those campaigns have used email accounts on WordPress and cPanel websites, which Microsoft is highly confident the group hacked for that purpose. Before, the group mostly used free email services such as Proton and Microsoft consumer accounts.

    Cybersecurity

    In 2025, the group delivered its malware through fake CAPTCHA pages that tricked targets into running commands themselves, a method known as ClickFix. This year it switched to a method Microsoft calls RedFlick. RedFlick uses scheduled tasks, jobs that Windows runs automatically, to install a backdoor named CosmicPulse.

    The invitations name well-known think tanks or NGOs as hosts, such as Chatham House and the Atlantic Council. Many emails are written to appear to come from within the target’s organization.

    The first email usually carries no attachment. If the target replies, the group sends a password-protected RAR or ZIP archive, with the password shown in an image.

    The first campaigns, in January and February, posed as Ukrainian authorities and sent fake tax audit and fine notices to users of the Ukrainian email service Ukr.net. Later lures included a water shutdown notice for hotels in Kyiv and a payment notice for staff at an international financial organization.

    One March campaign worked differently. People who replied to an Atlantic Council-themed invitation got a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor, according to Microsoft.

    Proofpoint reported Atlantic Council-themed emails from the group in March, along with a sharp rise in its email volume.

    Trellix found 4 such emails sent on March 26. Its confidence that the emails led to DarkSword is medium, because the exploit pages were offline and no exploit code was recovered.

    How the Backdoor Gets In

    Microsoft traced several versions of the infection chain. In all of them, a shortcut (LNK) file disguised as a PDF initiates the attack, and a Windows Installer (MSI) package sets up scheduled tasks.

    Opening the shortcut quietly runs commands that fetch the installer from a remote server. In January, a hidden script used the SSH program to download it. In July, the shortcut downloaded a PDF with a hidden command that tries to fetch the installer.

    In the version seen in April, the installer created 3 scheduled tasks named to look like normal network components:

    • Internet Quality Test Connection
    • Network Configuration Manager
    • System Health Monitor

    The first task sends the computer name and user name to the group’s command-and-control (C2) server and can run more code from a remote location. The second sets up WebDAV, a Windows feature that opens a web address as if it were a folder. The third uses control.exe, the Windows Control Panel program, to run the next stage from the C2 server.

    The next stage is a downloader disguised as a Control Panel item. It installs CosmicPulse, a Python-based backdoor. The downloader is the one earlier reports called NOROBOT or BAITSWITCH.

    Microsoft says these techniques overlap with a June campaign, reported by Digital Security Lab Ukraine, that targeted Ukrainian civil society organizations. That campaign used fake invitations to the Ukraine Recovery Conference. The lab did not name the attackers and could not recover the final payload.

    Cybersecurity

    Two indicators appear in both Microsoft’s list and the June report, a comparison by The Hacker News found: the IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com. Sharing them does not by itself show that the same group ran both campaigns.

    What Defenders Can Check

    Microsoft published hunting queries and indicators for the campaigns, with advice for government bodies, NGOs, and think tanks that work on or support Ukraine policy. It also notifies customers it sees as targeted or compromised.

    One domain, secure-dns-hub[.]com, was still in use when Microsoft published the report on September 29, according to the company.

    Organizations likely to be targeted can take these steps:

    • Check sender addresses. In these campaigns, the real organization’s name appears before the @ sign rather than in the domain. When in doubt, contact the sender through a phone number or email address you already know.
    • Search for the 3 scheduled task names above and for the Microsoft Defender detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
    • Widen the time range of Microsoft’s 3 Defender XDR hunting queries, which look back only 7 days as published. Defender’s advanced hunting keeps up to 30 days of raw data, so checking back to January needs logs kept longer, for example in Microsoft Sentinel.
    • Block or limit outbound SSH connections the business does not need. The January version used SSH to fetch its installer.
    • If you use Microsoft Defender, turn on the attack surface reduction rules that block rare, new, or untrusted executable files and obfuscated scripts.
    • Use phishing-resistant sign-in methods. The group still runs password phishing with Evilginx, a tool that can also steal session cookies to get around two-factor authentication.
    • Update iPhones to iOS 26.3 or later, which fixes all 6 flaws DarkSword uses, and turn on Lockdown Mode where that is not yet possible, Trellix advises.

    Microsoft’s public report does not list specific cleanup steps for a computer where the tasks are found. Defender XDR customers can check the company’s threat analytics reports, which include recommended response actions.

    Backdoor Blizzard deliver Event Fake invites Organizations Russias star targets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

    French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

    FBI tells ShinyHunters members to turn themselves in after recent arrest

    New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

    Former US Air Force members sent to prison over BEC attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ethereum Gets Another Privacy Boost as Aztec Brings Back zk.money

    September 30, 2026

    NASA Opens 2027 Human Lander Challenge for Lunar Communications

    September 30, 2026

    China Brief: Was Xi’s Meeting With Trump a Bust?

    September 30, 2026

    News live: Alan Kohler announces retirement from ABC after 31 years; six Australian universities in top 100 global rankings | Australia news

    September 30, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ethereum Gets Another Privacy Boost as Aztec Brings Back zk.money

    September 30, 2026

    NASA Opens 2027 Human Lander Challenge for Lunar Communications

    September 30, 2026

    China Brief: Was Xi’s Meeting With Trump a Bust?

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.