Security1 publisher3 min readPublished
Star Blizzard now sends its Ukraine lures from hacked WordPress and cPanel sites
Microsoft says Star Blizzard has sent fake event invitations to more than 100 organizations since January, many from hacked WordPress and cPanel sites. The group, long known for stealing email passwords, now uses the messages to install a Windows backdoor.
The Watch · Security desk

What happened
- Security agencies in the US, UK, Australia, Canada and New Zealand said in December 2023 that the group almost certainly works under Center 18 of Russia's FSB.
- Microsoft counted at least 13 larger campaigns this year, each running tens to hundreds of emails, on top of the group's routine targeted phishing.
- Early lures posed as Ukrainian authorities with fake tax audit and fine notices for Ukr.net users, and later ones included a water shutdown notice for Kyiv hotels.
- At least one computer is confirmed infected, but the number of breached organizations has not been disclosed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Staff at Ukraine-linked think tanks and NGOs now get these lures from real websites' mail accounts, so blocking or down-scoring free-mail senders catches less of this group's traffic.
- constraint Gateway checks on the first message have nothing malicious to inspect, so the outcome turns on whether a staff member answers an unexpected invitation.
- capability Endpoint teams can hunt for the task names, for control.exe pulling a stage from a remote server, and for the shared IP and domain, whether or not the mail was caught.
- contradiction Microsoft ties a March Atlantic Council wave to the DarkSword iPhone kit, but Trellix gives that link only medium confidence, so the iPhone risk from this group is less well established than the Windows chain.
Until March, Star Blizzard mostly sent its phishing from free services such as Proton and Microsoft consumer accounts [9]. Since then its larger campaigns have come from mail accounts on WordPress and cPanel websites. Microsoft is highly confident the group hacked those sites for that purpose [8]. Many messages are also written to look as if they came from inside the target's own organization, with invitations naming hosts such as Chatham House and the Atlantic Council [11]. A free-mail address sending a think-tank invitation is easy to flag. A message from an existing website's own mail server gives a filter that weighs sender reputation less to go on. The reported findings do not say how many of the messages were delivered.
The first email usually has no attachment [12]. A reply brings a password-protected RAR or ZIP archive, with the password shown in an image [12]. The conversation step is older. By 2023 the group was already using conference invitations as bait and often exchanged messages with a target before sending a malicious link [6].
What follows the reply has changed from year to year. In 2025 the group used ClickFix, fake CAPTCHA pages that got targets to run commands themselves. This year it switched to a method Microsoft calls RedFlick, built on Windows scheduled tasks [10]. Every version Microsoft traced starts with a shortcut file disguised as a PDF, and a Windows Installer package sets up the tasks [17]. The download step varies. In January a hidden script used SSH; in July the shortcut fetched a PDF carrying a hidden command [17].
The April installer created three tasks named Internet Quality Test Connection, Network Configuration Manager and System Health Monitor [18]. The first sends the computer and user name to the command server and can run remote code. The second sets up WebDAV. The third uses control.exe to run the next stage from the command server [18]. That stage is a downloader disguised as a Control Panel item, and it installs the Python-based backdoor CosmicPulse [19]. Earlier reports called the same downloader NOROBOT or BAITSWITCH [19].
Infection takes several deliberate steps. The target replies, opens an archive with a password read off an image, and runs a shortcut [12][17]. The campaigns are aimed at people and organizations tied to Ukraine, mostly in the US and UK [2]. Outside that group, this is a low priority. Inside it, the larger waves alone come to at least 130 messages this year [1]. Proofpoint reported a sharp rise in the group's email volume in March [15].
Microsoft says the techniques overlap with a June campaign against Ukrainian civil society groups that used fake Ukraine Recovery Conference invitations [20]. Digital Security Lab Ukraine, which reported that campaign, did not name the attackers and could not recover the final payload [20]. A comparison by The Hacker News found the IP address 103.160.59[.]97 and the domain secure-dns-hub[.]com in both Microsoft's indicator list and the June report [21]. Shared indicators do not by themselves show that one group ran both [21].
What to watch
- A disclosed count of breached organizations beyond the single confirmed infected computer.
- Recovery of DarkSword exploit code from the March Atlantic Council emails, which would settle Trellix's medium-confidence link.
- Further indicators or a final payload tying the June Ukraine Recovery Conference campaign to Star Blizzard.