Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Microsoft says Star Blizzard ran 13 fake-event-invite campaigns since January, hitting 100+ Ukraine-linked organizations with the CosmicPulse backdoor via scheduled tasks.
Microsoft attributes at least 13 spearphishing campaigns since January to Russia's Star Blizzard (FSB Center 18), affecting over 100 organizations tied to Ukraine, mostly in the U.S. and U.K. The group uses hacked WordPress and cPanel email accounts and lures posing as Chatham House and Atlantic Council events; targets who reply receive password-protected RAR/ZIP archives with LNK files that fetch an MSI installer. The RedFlick loader creates three disguised scheduled tasks to install CosmicPulse, a Python-based backdoor; one March campaign delivered the DarkSword iPhone exploit kit instead. Microsoft published hunting queries and indicators, and secure-dns-hub[.]com was still active at publication.