Russian cybercriminals, identified as the Star Blizzard group, have been orchestrating a series of phishing attacks using fraudulent event invitations to install malicious software on Windows computers. According to Microsoft, these campaigns have predominantly targeted individuals and organizations linked to Ukraine, affecting over 100 entities since January. The bulk of these efforts have been concentrated in the U.S. and U.K., though the exact number of compromised systems remains undisclosed.
Targeted Campaigns and Tactics
Star Blizzard is believed to operate under Russia’s Federal Security Service, specifically Center 18. The group is notorious for stealing email credentials by impersonating familiar contacts of their targets. In 2023, they intensified their tactics with over 13 large-scale campaigns, each comprising tens to hundreds of phishing emails. Initially, these campaigns utilized hacked accounts on platforms like WordPress and cPanel for distribution, moving away from previously used free email services such as Proton and Microsoft accounts.
The attackers employed a novel method named RedFlick to deliver a backdoor called CosmicPulse. This involves creating scheduled tasks on Windows systems, which are automated processes that facilitate the installation of the backdoor. The group cleverly disguises their communications as legitimate invitations from prominent think tanks and NGOs, enticing targets to engage with the content.
Evolution of Attack Strategies
Star Blizzard’s approach evolved significantly in 2025, shifting from using fake CAPTCHA pages to a more sophisticated RedFlick method. RedFlick leverages Windows’ scheduling capabilities to install malicious software silently. The group typically initiates contact with an email that appears genuine but contains no attachments. Upon receiving a response, they send a password-protected archive, with the password included as an image, to further lure their targets.
In some instances, such as a March campaign themed around an Atlantic Council event, recipients were directed to a link associated with an iPhone exploit kit known as DarkSword, rather than the Windows-targeted backdoor. This tactic highlights the group’s adaptability and their use of varied methods to compromise different systems.
Defensive Measures and Recommendations
Microsoft has released queries and indicators to help organizations defend against these threats, particularly those involved in Ukrainian policy. Vigilance in verifying sender addresses, monitoring for specific scheduled task names, and employing phishing-resistant authentication methods are crucial steps in mitigating risk. Organizations are also advised to utilize advanced security features in Microsoft Defender and to update iOS devices to the latest version to protect against known vulnerabilities exploited by these campaigns.
Microsoft emphasizes the importance of proactive measures, such as extending data logs for broader analysis and restricting unnecessary SSH connections, to prevent further infiltration. While the company’s public report does not detail cleanup steps for infected systems, Defender XDR customers are encouraged to consult Microsoft’s threat analytics for comprehensive response strategies.
The ongoing threat posed by Star Blizzard underscores the need for robust cybersecurity protocols and continued vigilance against evolving attack vectors. As these campaigns persist, organizations must prioritize security updates and user education to safeguard their networks.
