Russia's Star Blizzard Targets 100+ Ukraine-Linked Orgs With Fake Event Invites
Microsoft has linked Russia's FSB-affiliated hacking group Star Blizzard to a campaign targeting over 100 organizations connected to Ukraine policy, primarily in the US and UK, beginning in January 2026. The attackers sent fake event invitations impersonating well-known think tanks such as Chatham House and the Atlantic Council to lure victims into downloading a new malware chain called RedFlick, which installs a Python backdoor named CosmicPulse. At least one confirmed infection has been identified across at least 13 large-scale campaigns, though the total number of breached organizations has not been disclosed. The group, assessed with high confidence to operate under Center 18 of Russia's FSB, marked a tactical shift by moving from its traditional credential-phishing methods to full malware delivery, using email accounts hosted on compromised WordPress and cPanel websites to evade reputation-based filters. Microsoft has published detection signatures and threat-hunting queries to help defenders identify and respond to the activity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in