INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Star Blizzard Targets 100+ Organizations with Fake Event Invites

| 2026-10-05 11:01 CRITICAL HIGH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
On October 5, 2026, a Russian state threat group known as Star Blizzard, also referred to as Callisto Group and SEABORGIUM, associated with Centre 18 of Russia's Federal Security Service, carried out phishing and malware delivery activity affecting over 100 organizations primarily in the United States and the United Kingdom. The attackers created accounts on compromised websites running WordPress or cPanel to send phishing emails at a larger scale, using techniques such as RedFlick, which creates scheduled tasks to deploy their CosmicPulse backdoor. This attack is believed to have started with targeted spear-phishing campaigns against Ukrainian individuals, government agencies, NGOs, and think tanks focused on international policy before expanding internationally; Microsoft assesses the group's high confidence in this assessment.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

se•••••.com
ds•••••.org
co•••••.exe
SS•••••.exe
co•••••.exe
103.160.•••.•••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Star BlizzardStar Blizzard
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎between January 2023
Threat actors associated with Star Blizzard sent fake event invites to more than 30 civil society organizations between January 2023 and August 2024.
tactic Phishing
threat_actor Star Blizzard
source_region United States
organisation US Department of Justice
general_metric 100 websites
victims 30 society organizations
‎December 2023
Threat actors using Star Blizzard sent fake event invites to over 100 organizations in the U.S., U.K., Australia, Canada, and New Zealand.
threat_actor Star Blizzard
general_metric 18 Centre
target_region Russian Federation
target_region Australia
target_region Canada
target_region New Zealand
attribution Center 18
attribution Federal Security Service
‎August 2024
Star Blizzard used phishing to target more than 30 civil society organizations between January 2023 and August 2024.
tactic Phishing
threat_actor Star Blizzard
source_region United States
organisation US Department of Justice
general_metric 100 websites
victims 30 society organizations
‎January 2026
Threat actors used fake event invites to target at least 100+ organizations worldwide with phishing campaigns identified by Microsoft since January 2026.
tactic Phishing
organisation Microsoft
general_metric 13 scale phishing campaigns
‎March 26
Threat actors used fake event invites sent via Trellix to target 100+ organizations on March 26.
organisation Trellix
general_metric 4 such emails
‎September 29
Threat actors used the compromised secure-dns-hub[.]com domain to send fake event invitations targeting over 100 organizations on September 29.
‎2026/10/05
Star Blizzard, a Russian state threat group associated with Centre 18 of Russia's Federal Security Service, has targeted over 100 organizations in the US and UK using fake event invitations to trick people into installing a backdoor on their Windows computers.
threat_actor Star Blizzard
organisation Centre 18
organisation Federal Security Service
infrastructure Windows
organisation Microsoft
victims 100 organizations
organisation RedFlick Technique
organisation WordPress
organisation cPanel
organisation EDR
organisation RedFlick Reduces User Interaction
organisation RedFlick
organisation Digital Security Lab Ukraine
organisation the Ukraine Recovery Conference
organisation SSH.exe
organisation MSI
organisation LNK
organisation PDF
organisation CosmicPulse
organisation NOROBOT
organisation BAITSWITCH
organisation YESROBOT
organisation ClickFix
organisation CAPTCHA
organisation RAR
organisation Virtual Hard Disk
organisation VHDX
organisation DLL
organisation Atlantic Council
organisation DarkSword
organisation the Windows
organisation Script/RedFlick
infrastructure Ios
infrastructure 26.3
organisation Update iPhones
organisation Chatham House
organisation the Atlantic Council
organisation SSH
organisation The Hacker News
organisation IP
organisation Microsoft Sentinel
organisation Microsoft Defender
Tactical Metrics
Metrics
victims
100
Organizations
Metrics
victims
30
Society Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎26.3
Software Version