· via dev.to (home feed)
Star Blizzard's fake event invites delivered CosmicPulse backdoor to 100+ organizations
Microsoft says FSB-linked Star Blizzard targeted 100+ organizations with fake think-tank event invites that install a new Python backdoor using Windows scheduled tasks.

Fake invitations for a real backdoor
Microsoft has attributed a year-long spear-phishing effort to Star Blizzard, a group that security agencies in the U.S., U.K., Australia, Canada and New Zealand assessed in December 2023 as almost certainly operating under Center 18 of Russia's FSB. According to the findings reported by dev.to, more than 100 organizations — mostly in the U.S. and U.K. and tied to Ukraine policy — have received forged event invitations since January 2026 designed to plant a Python backdoor called CosmicPulse on Windows machines. Microsoft counted at least 13 larger campaigns, each involving tens to hundreds of emails, and confirmed at least one infected computer, though it has not said how many organizations were ultimately breached. One command-and-control domain was still live when Microsoft published its report on September 29.
The campaign is a shift for a group best known for credential phishing: impersonating people the target knows and stealing their email passwords. This year it added a complete malware delivery chain alongside its usual one-to-one phishing. Proofpoint separately observed a sharp rise in the group's email volume in March.
Lures built to dodge mail scanning
The invitations name well-known institutions such as Chatham House and the Atlantic Council as hosts, and many are written to look like internal messages from the target's own organization. The first email usually carries no attachment. Only if the target replies does the group send a password-protected RAR or ZIP archive, with the password shown in an image rather than text — keeping both the password and the archive contents out of reach of text-based mail scanning. Earlier waves posed as Ukrainian authorities sending fake tax audit notices to Ukr.net users; later lures included a water shutdown notice aimed at Kyiv hotels and a payment notice for staff at an international financial organization.
Since March, the emails have been sent from accounts on WordPress and cPanel websites that Microsoft assesses with high confidence were hacked for sending purposes — a change from the group's earlier reliance on Proton and Microsoft consumer accounts. Mail from established domains with clean histories weakens reputation-based filtering, and the impersonated organization's name appears before the @ sign while the domain belongs to an unrelated compromised site.
RedFlick and CosmicPulse
Delivery runs through what Microsoft calls RedFlick, which uses Windows scheduled tasks to install the backdoor. Every version Microsoft traced starts with a shortcut file disguised as a PDF and uses a Windows Installer package to create the tasks. In the April version, the installer created three tasks named to resemble routine network components: one sends the computer and user names to a command-and-control server and can pull down additional code; one enables WebDAV, which mounts a web address as a local folder; and one uses control.exe, the Windows Control Panel program, to run the next stage from the server.
That next stage is a downloader disguised as a Control Panel item, previously reported under the names NOROBOT or BAITSWITCH, which installs CosmicPulse. Pairing WebDAV with control.exe means execution flows through built-in Windows programs rather than a standalone executable dropped on disk. The initial fetch method evolved over the year: a hidden script used SSH in January, while by July the shortcut downloaded a PDF carrying a hidden command.
An iPhone branch
One March campaign worked differently. According to Microsoft, people who replied to an Atlantic Council-themed invitation received a link to DarkSword, an iPhone exploit kit, instead of the Windows payload. Trellix identified four such emails sent on March 26 and rates its confidence as medium, since the exploit pages were offline and no exploit code was recovered. Apple's iOS 26.3 patches all six vulnerabilities tied to the kit.
Microsoft also notes technical overlap with a June campaign reported by Digital Security Lab Ukraine, which targeted Ukrainian civil society with fake Ukraine Recovery Conference invitations. The Hacker News found a shared IP address and domain across the two reports, though shared infrastructure alone does not prove the same actors were behind both.
Detection and guidance
Microsoft published indicators of compromise, three Defender XDR hunting queries and the detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse. As published, the queries look back only 7 days while Defender advanced hunting retains 30 days of raw data, so activity dating to January appears only where logs — for example in Microsoft Sentinel — are kept longer. Recommended mitigations include confirming invitations through contact details already on file, limiting outbound SSH the business does not need, attack surface reduction rules that block untrusted executables and obfuscated scripts, and phishing-resistant sign-in. The group still runs password phishing with Evilginx, which steals session cookies to bypass two-factor authentication.
Why it matters
Star Blizzard is a credential-theft operator that has moved into persistent endpoint access, and its delivery chain is engineered against the controls most organizations rely on: hacked sending domains defeat reputation checks, image-based archive passwords defeat content scanning, and built-in Windows binaries sidestep executable blocking. For government bodies, NGOs, think tanks and financial firms working on Ukraine policy — and the companies that support them — a conference invitation is now an active attack path. With the number of breached organizations still unquantified and a command-and-control domain live at publication, the full impact remains an open question.
- #cybersecurity
- #malware
- #phishing
- #microsoft
- #windows