Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
- ID
- 29997
- Status
- summarized
- Published
- 30 Sep 2026, 1:20 AM
- Fetched
- 30 Sep 2026, 4:16 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.0
- Created
- 30 Sep 2026, 4:17 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
Microsoft says Russia's Star Blizzard ran at least 13 larger phishing campaigns since January against 100+ organizations tied to Ukraine, mostly in the U.S. and U.K., with at least one machine confirmed infected. The lures impersonate think tanks and NGOs such as Chatham House and the Atlantic Council, and the first email carries no attachment: only if the target replies does the group send a password-protected RAR or ZIP with the password shown in an image. Delivery this year uses a method Microsoft calls RedFlick, which abuses Windows scheduled tasks to install a backdoor named CosmicPulse, replacing 2025's ClickFix fake-CAPTCHA approach, and since March the emails have come from compromised WordPress and cPanel site accounts instead of free services like Proton.
Why it matters
The reply-gated, password-in-an-image archive is a concrete gap: nothing malicious arrives in the first message, so attachment sandboxing and link scanners see a clean email. If your team's playbook says 'no attachment, no risk,' it needs a rule about replying to unexpected event or conference invitations. The WordPress/cPanel detail also matters locally — if you or a client run mail on shared cPanel hosting, a compromised mailbox there can be repurposed to send these lures, so check outbound mail logs and scheduled tasks, not just inbound filters.
Discussion angle
If the first email is benign and the payload only arrives after you reply, which detection layer in your stack would actually catch it — and is there a way to test that this week?