Build1 publisher2 min readPublished
Star Blizzard now delivers the CosmicPulse backdoor through fake event invitations
Microsoft says Russia's FSB-linked Star Blizzard sent fake event invitations to more than 100 organizations since January 2026. The lures pose as Chatham House and Atlantic Council events and carry a new Python backdoor, CosmicPulse, aimed at people working on Ukraine.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Long known for credential phishing, the group this year added a full malware delivery chain, a departure from operations that mostly stole email passwords.
- Microsoft counted at least 13 larger campaigns in 2026, each with tens to hundreds of emails, running on top of the group's usual one-to-one phishing.
- Microsoft has confirmed at least one infected computer but has not said how many of the targeted organizations were actually breached.
- Microsoft published indicators of compromise, three Defender XDR hunting queries and the detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
- Apple's iOS 26.3 update fixes all six flaws tied to the DarkSword exploit kit.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint The chain is built so the two automatic controls most mail teams lean on, content scanning and sender-reputation scoring, produce little to alert on; catching it falls to the endpoint and to a person noticing the invitation is off.
- exposure At least one campaign steered targets to an iPhone exploit kit, so unpatched staff phones stay reachable, not only the Windows machines the backdoor lands on.
- capability The named detections and hunting queries give a team something to run against telemetry it already holds, so a quiet compromise can surface before the next email arrives.
Every RedFlick sample Microsoft traced starts the same way. A shortcut file disguised as a PDF arrives, and opening it quietly runs commands that pull a Windows Installer package from a remote server; that package then creates scheduled tasks. [16] The download step changed over the year. In January a hidden script used SSH to fetch the installer. By July the shortcut downloaded a PDF that carried a hidden command to fetch it instead. [17]
In the April build, the installer created three scheduled tasks named to pass for network plumbing. One, called "Internet Quality Test Connection," sends the machine's computer name and user name to the command-and-control server and can pull down more code. [18] One of those command-and-control domains was still live when Microsoft published on September 29. [8] Microsoft calls this chain RedFlick; in 2025 the group used ClickFix instead, fake CAPTCHA pages that talked users into running the commands themselves. [15]
The mail around it is built to give a gateway little to catch. The first message has no attachment. Reply to it and a password-protected RAR or ZIP comes back, with the password sitting inside an image, so a text scanner reads neither the password nor the archive contents. [9] Since March the messages have come from accounts on hacked WordPress and cPanel sites. Microsoft is highly confident the group broke into those sites itself; earlier it leaned on Proton and consumer Microsoft accounts, and mail from established domains with clean histories weakens filtering that scores sender reputation. [10] The sender address puts the impersonated organisation's name before the @ and an unrelated hacked domain after it, so at a glance it looks like the real host. [11]
The attribution is settled. In December 2023 agencies in the United States, United Kingdom, Australia, Canada and New Zealand assessed that Star Blizzard almost certainly works under Center 18 of Russia's FSB. [12] That assessment said impersonation is the group's core method, and that it was already sending fake conference invitations, often trading several messages with a target before anything malicious arrived. [12] Proofpoint reported a sharp rise in the group's email volume in March. [13]
The lures follow the news. The January and February waves posed as Ukrainian authorities and pushed fake tax-audit and fine notices to Ukr.net users. Later lures included a water-shutdown notice aimed at Kyiv hotels and a payment notice for staff at an international financial organisation. [14] The primary targets are government bodies, NGOs, think tanks and financial organisations that work on Ukraine policy, most of them in the United States and United Kingdom. [2]
What to watch
- Whether Microsoft discloses how many of the 100-plus targeted organizations were breached, beyond the single confirmed infection.
- Whether the command-and-control domain still live on September 29 gets taken down.
- Whether the group's email volume, up sharply in March per Proofpoint, keeps climbing through the year.