INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Star Blizzard Targets 100+ Organizations with Fake Event Invites
| 2026-10-05 11:01 CRITICAL HIGH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
On October 5, 2026, a Russian state threat group known as Star Blizzard, also referred to as Callisto Group and SEABORGIUM, associated with Centre 18 of Russia's Federal Security Service, carried out phishing and malware delivery activity affecting over 100 organizations primarily in the United States and the United Kingdom. The attackers created accounts on compromised websites running WordPress or cPanel to send phishing emails at a larger scale, using techniques such as RedFlick, which creates scheduled tasks to deploy their CosmicPulse backdoor. This attack is believed to have started with targeted spear-phishing campaigns against Ukrainian individuals, government agencies, NGOs, and think tanks focused on international policy before expanding internationally; Microsoft assesses the group's high confidence in this assessment.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
se•••••.com
ds•••••.org
co•••••.exe
SS•••••.exe
co•••••.exe
103.160.•••.•••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
between January 2023
Threat actors associated with Star Blizzard sent fake event invites to more than 30 civil society organizations between January 2023 and August 2024.
Click on any entity below to view its context and source!
tactic
Phishing
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
threat_actor
Star Blizzard
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
source_region
United States
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
organisation
US Department of Justice
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
general_metric
100 websites
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
victims
30 society organizations
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
December 2023
Threat actors using Star Blizzard sent fake event invites to over 100 organizations in the U.S., U.K., Australia, Canada, and New Zealand.
Click on any entity below to view its context and source!
threat_actor
Star Blizzard
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
general_metric
18 Centre
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
target_region
Russian Federation
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
target_region
Australia
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
target_region
Canada
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
target_region
New Zealand
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
attribution
Center 18
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
attribution
Federal Security Service
Security agencies in the U.S., U.K., Australia, Canada and New Zealand
said in December 2023
that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB).
August 2024
Star Blizzard used phishing to target more than 30 civil society organizations between January 2023 and August 2024.
Click on any entity below to view its context and source!
tactic
Phishing
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
threat_actor
Star Blizzard
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
source_region
United States
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
organisation
US Department of Justice
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
general_metric
100 websites
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
victims
30 society organizations
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
January 2026
Threat actors used fake event invites to target at least 100+ organizations worldwide with phishing campaigns identified by Microsoft since January 2026.
Click on any entity below to view its context and source!
tactic
Phishing
Since January 2026, Microsoft has identified at least 13 large-scale phishing campaigns targeting organizations worldwide.
organisation
Microsoft
Since January 2026, Microsoft has identified at least 13 large-scale phishing campaigns targeting organizations worldwide.
general_metric
13 scale phishing campaigns
Since January 2026, Microsoft has identified at least 13 large-scale phishing campaigns targeting organizations worldwide.
March 26
Threat actors used fake event invites sent via Trellix to target 100+ organizations on March 26.
Click on any entity below to view its context and source!
organisation
Trellix
Trellix
found 4 such emails sent on March 26.
general_metric
4 such emails
Trellix
found 4 such emails sent on March 26.
September 29
Threat actors used the compromised secure-dns-hub[.]com domain to send fake event invitations targeting over 100 organizations on September 29.
2026/10/05
Star Blizzard, a Russian state threat group associated with Centre 18 of Russia's Federal Security Service, has targeted over 100 organizations in the US and UK using fake event invitations to trick people into installing a backdoor on their Windows computers.
Click on any entity below to view its context and source!
threat_actor
Star Blizzard
Microsoft Threat Intelligence has detailed new phishing and malware delivery activity from Star Blizzard, a Russian state threat group.
The group, also known as
Callisto Group
and
SEABORGIUM
, is associated with Centre 18 of Russia’s Federal Security Service,
according to
the US Cybersecurity and Infrastructure Security Agency (CISA).
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
Russian state hackers known as
Star Blizzard
have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique.
To send phishing emails at a larger scale, Star Blizzard created accounts on
compromised websites running WordPress
or cPanel.
Phishing email used by Star Blizzard to deliver a password-protected malicious archive.
Star Blizzard has used targeted spear-phishing in earlier campaigns, including attacks against civil society organizations.
The latest activity highlights Star Blizzard’s use of large-scale phishing alongside less interactive malware delivery and scheduled tasks.
The changes give Star Blizzard a broader phishing reach while reducing the number of steps required to deliver CosmicPulse.
Star Blizzard’s VHDX infection chain uses a disguised LNK file and SSH.exe to download the CosmicPulse downloader.
Star Blizzard also targeted several people within the same organization, sending messages designed to appear as internal communications.
Source: Microsoft
RedFlick Reduces User Interaction
The most notable change is RedFlick, a technique that creates scheduled tasks to help deploy Star Blizzard’s CosmicPulse backdoor.
Source: Microsoft
Scheduled Tasks Aid Persistence
In April, Star Blizzard’s MSI installer created three scheduled tasks disguised as network tasks.
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor.
organisation
Centre 18
The group, also known as
Callisto Group
and
SEABORGIUM
, is associated with Centre 18 of Russia’s Federal Security Service,
according to
the US Cybersecurity and Infrastructure Security Agency (CISA).
organisation
Federal Security Service
The group, also known as
Callisto Group
and
SEABORGIUM
, is associated with Centre 18 of Russia’s Federal Security Service,
according to
the US Cybersecurity and Infrastructure Security Agency (CISA).
infrastructure
Windows
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
Russian state hackers known as
Star Blizzard
have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
In all of them, a shortcut (LNK) file disguised as a PDF initiates the attack, and a Windows Installer (MSI) package sets up scheduled tasks.
RedFlick uses scheduled tasks, jobs that Windows runs automatically, to install a backdoor named CosmicPulse.
People who replied to an Atlantic Council-themed invitation got a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor, according to Microsoft.
The second sets up WebDAV, a Windows feature that opens a web address as if it were a folder.
The third uses control.exe, the Windows Control Panel program, to run the next stage from the C2 server.
organisation
Microsoft
Russian state hackers known as
Star Blizzard
have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
victims
100 organizations
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique.
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor.
The activity affected more than 100 organizations, primarily in the United States and the United Kingdom.
The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been disclosed.
organisation
RedFlick Technique
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique.
organisation
WordPress
To send phishing emails at a larger scale, Star Blizzard created accounts on
compromised websites running WordPress
or cPanel.
Since March, those campaigns have used email accounts on WordPress and cPanel websites, which Microsoft is highly confident the group hacked for that purpose.
organisation
cPanel
To send phishing emails at a larger scale, Star Blizzard created accounts on
compromised websites running WordPress
or cPanel.
Since March, those campaigns have used email accounts on WordPress and cPanel websites, which Microsoft is highly confident the group hacked for that purpose.
organisation
EDR
Microsoft recommends phishing-resistant authentication, EDR in block mode, and email and endpoint security controls to help organizations detect and block these attacks.
organisation
RedFlick Reduces User Interaction
Source: Microsoft
RedFlick Reduces User Interaction
The most notable change is RedFlick, a technique that creates scheduled tasks to help deploy Star Blizzard’s CosmicPulse backdoor.
organisation
RedFlick
Source: Microsoft
RedFlick Reduces User Interaction
The most notable change is RedFlick, a technique that creates scheduled tasks to help deploy Star Blizzard’s CosmicPulse backdoor.
This year it switched to a method Microsoft calls RedFlick.
organisation
Digital Security Lab Ukraine
Microsoft says these techniques overlap with a June campaign,
reported by Digital Security Lab Ukraine
, that targeted Ukrainian civil society organizations.
organisation
the Ukraine Recovery Conference
That campaign used fake invitations to the Ukraine Recovery Conference.
organisation
SSH.exe
The chain also used
SSH.exe
with PermitLocalCommand to download and execute the MSI.
organisation
MSI
The chain also used
SSH.exe
with PermitLocalCommand to download and execute the MSI.
In all of them, a shortcut (LNK) file disguised as a PDF initiates the attack, and a Windows Installer (MSI) package sets up scheduled tasks.
organisation
LNK
In all of them, a shortcut (LNK) file disguised as a PDF initiates the attack, and a Windows Installer (MSI) package sets up scheduled tasks.
Microsoft researchers noted password-protected ZIP or RAR archives containing files such as Virtual Hard Disk (VHDX) images and shortcut (LNK) files.
organisation
PDF
In all of them, a shortcut (LNK) file disguised as a PDF initiates the attack, and a Windows Installer (MSI) package sets up scheduled tasks.
In one January chain, a VHDX contained an LNK disguised as a PDF, which led to an
MSI installer
.
organisation
CosmicPulse
The CosmicPulse downloader is also known as NOROBOT or BAITSWITCH, while the backdoor payload is also called YESROBOT.
RedFlick uses scheduled tasks, jobs that Windows runs automatically, to install a backdoor named CosmicPulse.
organisation
NOROBOT
The CosmicPulse downloader is also known as NOROBOT or BAITSWITCH, while the backdoor payload is also called YESROBOT.
The downloader is the one earlier reports called NOROBOT or
BAITSWITCH
.
organisation
BAITSWITCH
The CosmicPulse downloader is also known as NOROBOT or BAITSWITCH, while the backdoor payload is also called YESROBOT.
organisation
YESROBOT
The CosmicPulse downloader is also known as NOROBOT or BAITSWITCH, while the backdoor payload is also called YESROBOT.
organisation
ClickFix
Unlike the group’s earlier
ClickFix campaigns
, which required victims to complete several actions, the newer infection chain can begin with a single user action.
In 2025, the group delivered its malware through fake CAPTCHA pages that tricked targets into running commands themselves, a method known as
ClickFix
.
organisation
CAPTCHA
In 2025, the group delivered its malware through fake CAPTCHA pages that tricked targets into running commands themselves, a method known as
ClickFix
.
organisation
RAR
Microsoft researchers noted password-protected ZIP or RAR archives containing files such as Virtual Hard Disk (VHDX) images and shortcut (LNK) files.
If the target replies, the group sends a password-protected RAR or ZIP archive, with the password shown in an image.
organisation
Virtual Hard Disk
Microsoft researchers noted password-protected ZIP or RAR archives containing files such as Virtual Hard Disk (VHDX) images and shortcut (LNK) files.
organisation
VHDX
Microsoft researchers noted password-protected ZIP or RAR archives containing files such as Virtual Hard Disk (VHDX) images and shortcut (LNK) files.
organisation
DLL
One task can send encoded information about the device to a command-and-control server and invoke an attacker-controlled DLL through Control_RunDLL.
organisation
Atlantic Council
People who replied to an Atlantic Council-themed invitation got a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor, according to Microsoft.
organisation
DarkSword
People who replied to an Atlantic Council-themed invitation got a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor, according to Microsoft.
organisation
the Windows
The third uses control.exe, the Windows Control Panel program, to run the next stage from the C2 server.
organisation
Script/RedFlick
Search for the 3 scheduled task names above and for the Microsoft Defender detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
infrastructure
Ios
Update iPhones to iOS 26.3 or later, which fixes all 6 flaws DarkSword uses, and turn on Lockdown Mode where that is not yet possible, Trellix advises.
infrastructure
26.3
Update iPhones to iOS 26.3 or later, which fixes all 6 flaws DarkSword uses, and turn on Lockdown Mode where that is not yet possible, Trellix advises.
organisation
Update iPhones
Update iPhones to iOS 26.3 or later, which fixes all 6 flaws DarkSword uses, and turn on Lockdown Mode where that is not yet possible, Trellix advises.
organisation
Chatham House
The invitations name well-known think tanks or NGOs as hosts, such as Chatham House and the Atlantic Council.
organisation
the Atlantic Council
The invitations name well-known think tanks or NGOs as hosts, such as Chatham House and the Atlantic Council.
organisation
SSH
In January, a hidden script used the SSH program to download it.
organisation
The Hacker News
Two indicators appear in both Microsoft's list and the June report, a comparison by The Hacker News found: the IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com.
organisation
IP
Two indicators appear in both Microsoft's list and the June report, a comparison by The Hacker News found: the IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com.
organisation
Microsoft Sentinel
Defender's advanced hunting keeps up to
30 days of raw data
, so checking back to January needs logs kept longer, for example in Microsoft Sentinel.
organisation
Microsoft Defender
If you use Microsoft Defender, turn on the attack surface reduction rules that block rare, new, or untrusted executable files and obfuscated scripts.
Tactical Metrics
Metrics
victims
100
Organizations
Click for context!
The activity affected more than 100 organizations, primarily in the United States and the United Kingdom.
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique.
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor.
The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been disclosed.
Metrics
victims
30
Society Organizations
In 2024, Hackread
reported
on a joint US Department of Justice and Microsoft operation that seized more than 100 websites linked to the group’s phishing infrastructure, after Microsoft found Star Blizzard had targeted more than 30 civil society organizations between January 2023 and August 2024.
Metrics
infrastructure
Windows
Affected Product
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
Russian state hackers known as
Star Blizzard
have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
RedFlick uses scheduled tasks, jobs that Windows runs automatically, to install a backdoor named CosmicPulse.
People who replied to an Atlantic Council-themed invitation got a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor, according to Microsoft.
In all of them, a shortcut (LNK) file disguised as a PDF initiates the attack, and a Windows Installer (MSI) package sets up scheduled tasks.
The second sets up WebDAV, a Windows feature that opens a web address as if it were a folder.
The third uses control.exe, the Windows Control Panel program, to run the next stage from the C2 server.
Metrics
infrastructure
Ios
Affected Product
Update iPhones to iOS 26.3 or later, which fixes all 6 flaws DarkSword uses, and turn on Lockdown Mode where that is not yet possible, Trellix advises.
Metrics
infrastructure
26.3
Software Version
Update iPhones to iOS 26.3 or later, which fixes all 6 flaws DarkSword uses, and turn on Lockdown Mode where that is not yet possible, Trellix advises.
Intelligence Sources
The Hacker News
2026-09-29
HackRead
2026-10-05
AlienVault OTX
2026-09-29
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:44
Comprehensive Tactical Telemetry
Highly Correlated Entities
39x
organisation
Identified Entity
Centre 18
entity
12x
timeline
Temporal Reference
2024
date
7x
target region
Target Country
United States
country
5x
attribution
Attributing Entity
Microsoft Threat Intelligence
authority
4x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
3x
source region
Origin Country
Russian Federation
country
2x
industry
Targeted Sector
Government
sector
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
11 METRICS
tactic
Cyber Operation Type
Phishing
tactic
threat actor
APT Group
Star Blizzard
actor
general metric
Centre
18
centre
victims
Organizations
100
organizations
general metric
Websites
100
websites
victims
Society Organizations
30
society organizations
general metric
Scale Phishing Campaigns
13
scale phishing campaigns
general metric
Scheduled Tasks
3
scheduled tasks
infrastructure
Software Version
26.3
version
general metric
Flaws
6
flaws
general metric
Such Emails
4
such emails
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.