- What: Russia's FSB-linked Star Blizzard sent fake Chatham House and Atlantic Council event invitations that led to a new infection chain, RedFlick, which installs the Python backdoor CosmicPulse.
- Impact: More than 100 organizations tied to Ukraine, mostly in the U.S. and U.K., were targeted across at least 13 larger campaigns, with at least one confirmed infection and the number of breached organizations not disclosed.
- Fix / mitigation: Microsoft published indicators, 3 Defender XDR hunting queries and the detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse, and Apple's iOS 26.3 fixes all 6 flaws tied to the DarkSword exploit kit.
- Who's at risk: Government bodies, NGOs, think tanks and financial organizations that work on or support Ukraine policy are the primary targets.
Microsoft says Russia's FSB-linked Star Blizzard has sent fake event invitations to more than 100 organizations since January 2026. The goal is to plant a Python backdoor called CosmicPulse on Windows machines. Targets are people and organizations tied to Ukraine, mostly in the U.S. and U.K. Microsoft confirmed at least one infected computer but has not said how many organizations were breached. One command-and-control domain was still active when Microsoft published its report on September 29.
This is a change in how the group operates. Star Blizzard is best known for credential phishing. This year it added a full malware delivery chain and mail infrastructure taken from hacked websites, and in at least one campaign it sent targets to an iPhone exploit kit.
Who Star Blizzard Is
In December 2023, security agencies in the U.S., U.K., Australia, Canada and New Zealand assessed that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB). Its core method is impersonation: it poses as people the target knows and steals their email passwords. By 2023 it was already using fake conference invitations, and it often traded several messages with a target before sending anything malicious.
Microsoft counted at least 13 larger campaigns in 2026, each with tens to hundreds of emails. These ran on top of the group's usual one-to-one phishing. Proofpoint separately reported a sharp rise in the group's email volume in March.
Lures and Sending Infrastructure
The invitations name well-known think tanks and NGOs as hosts, including Chatham House and the Atlantic Council. Many are written to look like they come from inside the target's own organization. The first email usually has no attachment. If the target replies, the group sends a password-protected RAR or ZIP archive and shows the password in an image. That keeps both the password and the archive contents out of reach of text-based mail scanning.
Since March, the campaigns have been sent from email accounts on WordPress and cPanel websites. Microsoft is highly confident the group hacked those sites to use them for sending. Before that, Star Blizzard mostly used free services such as Proton and Microsoft consumer accounts. Mail from established domains with clean histories weakens filtering that relies on sender reputation.
In these campaigns, the impersonated organization's name appears before the @ sign, and the domain belongs to an unrelated hacked website. At a glance, the address looks like it comes from the real host organization.
The January and February waves posed as Ukrainian authorities and sent fake tax audit and fine notices to users of Ukr.net. Later lures included a water shutdown notice aimed at hotels in Kyiv and a payment notice for staff at an international financial organization.
From ClickFix to RedFlick
In 2025, Star Blizzard delivered malware through ClickFix: fake CAPTCHA pages that trick users into running commands themselves. In 2026 it switched to a method Microsoft calls RedFlick, which uses Windows scheduled tasks to install CosmicPulse.
Every version Microsoft traced begins with a shortcut (LNK) file disguised as a PDF and uses a Windows Installer (MSI) package to create scheduled tasks. Opening the shortcut quietly runs commands that fetch the installer from a remote server. How it fetched the installer changed over time. In January, a hidden script used SSH to download it. In July, the shortcut downloaded a PDF carrying a hidden command that tries to fetch it.
In the April version, the MSI created 3 scheduled tasks named to look like normal network components:
- Internet Quality Test Connection: sends the computer name and user name to the C2 server and can run more code from a remote location.
- Network Configuration Manager: sets up WebDAV, a Windows feature that opens a web address as if it were a local folder.
- System Health Monitor: uses control.exe, the Windows Control Panel program, to run the next stage from the C2 server.
The next stage is a downloader disguised as a Control Panel item. Earlier reports called it NOROBOT or BAITSWITCH. It installs CosmicPulse, a Python-based backdoor. Because WebDAV is paired with control.exe, the next stage runs through a built-in Windows program and not through a standalone executable dropped on disk.
The iPhone Branch
One March campaign worked differently. According to Microsoft, people who replied to an Atlantic Council-themed invitation got a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor. Trellix found 4 such emails sent on March 26. It rates its confidence that they led to DarkSword as medium, because the exploit pages were offline and no exploit code was recovered. iOS 26.3 fixes all 6 flaws tied to DarkSword.
Overlap With the Ukraine Recovery Conference Campaign
Microsoft says these techniques overlap with a June campaign reported by Digital Security Lab Ukraine. That campaign targeted Ukrainian civil society organizations with fake invitations to the Ukraine Recovery Conference. The lab did not name the attackers and could not recover the final payload. The Hacker News found two indicators in both Microsoft's list and the June report: the IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com. Shared infrastructure alone does not show that the same group ran both campaigns.
Vendor Guidance and Detection Coverage
Microsoft published indicators and 3 Defender XDR hunting queries, along with advice for government bodies, NGOs and think tanks that work on Ukraine policy. It also notifies customers it sees as targeted or compromised. The Defender detections for this activity are Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
As published, the hunting queries look back only 7 days. Defender advanced hunting keeps up to 30 days of raw data. Activity going back to January shows up only where logs are kept longer, for example in Microsoft Sentinel.
Mitigations cited in the reporting include confirming invitations through contact details already on file and limiting outbound SSH the business does not need, since the January version used it. They also include Defender attack surface reduction rules that block rare, new or untrusted executables and obfuscated scripts, and phishing-resistant sign-in. The group still runs password phishing with Evilginx, which can steal session cookies to get around two-factor authentication.
RedEye Assessment
Star Blizzard's 2026 activity shows a credential theft operator moving into persistent access on endpoints. Its delivery is built to get past the controls most organizations rely on: sender reputation checks, attachment scanning and blocking of unknown executables. It does this with hacked sending domains, image-based archive passwords and built-in Windows programs. Organizations working on Ukraine policy, and the firms that support them, should treat conference and event invitations as an active attack path. With confirmed infections still unquantified and one C2 domain live at publication, the full scope of this campaign is not yet known.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us