Microsoft’s latest analysis of Star Blizzard shows a Russian state-linked espionage operation becoming both broader and more efficient. Since January 2026, Microsoft has observed at least 13 large-scale phishing campaigns linked to the actor, with individual operations ranging from tens to hundreds of messages. More than 100 organizations have been affected, primarily in the United States and United Kingdom, while the wider targeting continues to include Ukrainian institutions, governments, NGOs, think tanks, diplomatic organizations, security researchers, academics, media organizations, financial institutions, and other entities involved in international policy or support for Ukraine.
The scale is notable because Star Blizzard has historically been associated with carefully tailored spear-phishing against selected individuals. In 2026, Microsoft observed the group begin combining that traditional social-engineering expertise with a more scalable phishing infrastructure. The result is not indiscriminate spam. The campaigns still use highly relevant geopolitical and professional themes, but they are now distributed to larger pools of strategically interesting targets.
That combination is important.
Mass phishing normally sacrifices personalization for volume.
Star Blizzard appears to be trying to retain credibility while increasing reach.
Microsoft assesses that the actor may now be using a mass-mailing phishing platform to automate campaign execution, allowing it to target significantly more organizations without abandoning its familiar pattern of building trust before delivering the malicious payload.
The first contact is often deliberately harmless. The email may contain no attachment or malware at all. Instead, the attacker sends what appears to be a legitimate invitation, policy discussion, conference request, tax notice, payment notification, or other professional communication. If the target replies, Star Blizzard follows up with the malicious component.
This is one of the reasons the campaign is effective.
The victim effectively validates themselves as an engaged target.
By responding, the recipient signals that the sender is believable, the topic is relevant, and future communication is likely to be opened.
The attacker then sends a password-protected RAR or ZIP archive, often presenting the password as an image within the email. Password-protected archives can reduce the effectiveness of some automated email-scanning systems because security products may be unable to inspect the enclosed content before delivery.
The social engineering themes are carefully matched to the intended audience. Microsoft observed campaigns impersonating organizations such as Chatham House, the Atlantic Council, the International Institute for Strategic Studies, and other policy or diplomatic bodies. Some messages were written to look as if they originated from people within the victim’s own organization.
That last technique is particularly dangerous because organizational familiarity is one of the strongest trust signals in email.
A recipient may scrutinize a message from an unknown foreign address.
They are much less likely to distrust an invitation that appears to come from a colleague, familiar think tank, research organization, or policy contact.
Star Blizzard has also changed how it obtains sending infrastructure. Since March 2026, Microsoft says the group has increasingly used accounts created on compromised WordPress and cPanel-hosted websites rather than relying exclusively on free consumer email services.
This gives the attackers several advantages.
Messages can originate from domains with existing reputation.
The domains may belong to legitimate organizations.
Email filtering systems may therefore treat them as less suspicious than newly registered attacker-controlled infrastructure.
The technique also demonstrates why website compromise can have consequences far beyond website defacement or data theft.
A compromised website can become infrastructure for attacks against completely unrelated organizations.
Star Blizzard’s most important technical evolution in 2026 is a delivery technique Microsoft calls RedFlick.
Earlier campaigns used ClickFix-style social engineering, where victims were tricked into manually copying or executing commands. That approach can be effective, but it requires several user actions and therefore creates opportunities for the victim to become suspicious.
RedFlick reduces that friction.
According to Microsoft, the infection chain now requires only a single meaningful victim interaction before Windows scheduled tasks take over the remaining malware deployment.
That shift is significant because every additional user action reduces the probability of successful compromise.
Removing steps improves conversion rates for attackers just as efficiently as it does for legitimate software onboarding, a depressing little example of user-experience optimization finding its natural home in espionage.
The technical chain has changed several times during 2026, but the broad objective remains consistent: deploy the CosmicPulse backdoor while blending malicious execution into legitimate Windows behavior.
In the January campaigns, Star Blizzard delivered password-protected ZIP files containing malicious VHDX images. Inside was an LNK shortcut disguised as a PDF together with supporting files.
When the victim opened the shortcut, Windows launched commands in the background and eventually invoked the legitimate ssh.exe binary to retrieve a remote MSI package.
That MSI installed a scheduled task that later executed the next stage.
By April, Star Blizzard had expanded the technique into three separate scheduled tasks designed to resemble legitimate Windows networking and health-monitoring components:
Internet Quality Test Connection
Network Configuration Manager
System Health Monitor
The names are intentionally mundane.
An administrator casually examining Task Scheduler could easily assume they belong to Windows or network-management software.
Each task performs a different function.
The first sends basic host information, including the computer name and username, to attacker infrastructure and provides a mechanism for remotely executing additional DLL content.
The second enables Windows WebDAV functionality so remote resources can be accessed using UNC-style paths over HTTP or HTTPS.
The third uses the legitimate Windows control.exe utility to retrieve and execute the next-stage payload from the attacker’s server.
This is a good example of living-off-the-land tradecraft.
Rather than introducing an obviously malicious executable for every step, Star Blizzard abuses legitimate Windows components such as Task Scheduler, Control Panel, WebDAV, SSH, PowerShell, curl, and conhost.exe.
Each individual component is normal.
The maliciousness comes from how they are combined.
The next stage installs CosmicPulse, a Python-based backdoor that has been associated with Star Blizzard activity previously. Microsoft says the downloader responsible for installing CosmicPulse has also been publicly tracked as NOROBOT or BAITSWITCH.
The downloader retrieves two ZIP archives.
One contains a Python 3.8 runtime and bootstrapper.
The second contains the encrypted CosmicPulse payload.
The bootstrapper retrieves an AES key stored in the Windows registry, decrypts it using an embedded key, and then uses the recovered value to decode and execute the backdoor.
The use of a bundled Python environment allows Star Blizzard to run its Python malware even where Python was never installed on the victim system.
This is a common technique among modern threat actors because it removes a dependency that would otherwise make malware execution less reliable.
Microsoft says the CosmicPulse payload itself has changed incrementally throughout the year, apparently to evade static signatures, while its overall capabilities and purpose remain largely consistent.
That is an important distinction for defenders.
Malware hashes and small byte signatures will change.
Behavior usually changes much more slowly.
Detection should therefore focus on the infection chain: suspicious LNK execution, unexpected scheduled-task creation, unusual WebDAV activity, control.exe loading remote CPL content, and abnormal use of SSH or PowerShell from document-related workflows.
Star Blizzard modified the chain again in July.
In that version, the victim received a ZIP containing a password-protected RAR archive. Opening the archive revealed an LNK file.
The shortcut used conhost.exe and curl to download what appeared to be a PDF.
The PDF itself contained embedded Base64-encoded command data after a marker inside the document.
PowerShell then extracted that hidden payload and executed it, leading to another MSI installer and another sequence of scheduled tasks.
This is essentially payload concealment inside an apparently legitimate document.
The PDF serves both as a decoy and a container for executable command material.
This complicates static analysis because the document itself may appear visually legitimate while carrying data that only becomes meaningful when processed by the attack chain.
Microsoft says this evolution reflects Star Blizzard’s continued effort to reduce required user interaction, improve malware-delivery reliability, and evade layered detection.
The group has also demonstrated flexibility across operating systems.
In one March campaign impersonating the Atlantic Council, users who engaged with the lure were reportedly redirected toward DarkSword, an iOS exploitation chain, instead of the Windows CosmicPulse infection flow.
That shows Star Blizzard is not simply distributing one fixed Windows malware package.
It is tailoring delivery based on the target, device, and campaign objective.
The broader pattern is espionage rather than financial crime.
The actor’s targeting remains concentrated on individuals and organizations possessing information relevant to Russian strategic interests, particularly those connected to Ukraine, Western foreign policy, diplomacy, defense, civil society, and international affairs.
Five Eyes cybersecurity agencies have previously assessed Star Blizzard as operating under Centre 18 of Russia’s Federal Security Service, the FSB. Microsoft likewise describes the actor as a Russian state threat actor.
That attribution is considerably stronger than the circumstantial country-linking seen in many cyber incidents and should therefore be distinguished from more speculative cases.
The campaign also demonstrates the limits of infrastructure takedowns.
Microsoft and U.S. authorities previously seized or disrupted more than 100 Star Blizzard-associated domains, and Microsoft says over 180 malicious websites associated with the actor have been taken down since October 2024.
Those operations increased the group’s costs and disrupted existing infrastructure, but they did not permanently remove the actor.
Instead, Star Blizzard changed its methods.
It began compromising legitimate websites.
It changed email infrastructure.
It modified malware-delivery chains.
It moved from ClickFix toward RedFlick.
It expanded campaign scale.
This is typical of mature state-backed operations.
Infrastructure disruption is valuable, but defenders should not assume it eliminates the underlying capability.
The actor adapts.
The targeting strategy itself also provides an important defensive clue.
Individuals working in government, diplomacy, journalism, academia, think tanks, NGOs, defense policy, and Ukraine-related programs should treat unexpected conference invitations or requests for closed-door discussions with greater skepticism than ordinary users might.
The message does not need to contain an obviously malicious link.
The first email may genuinely contain nothing harmful.
Its purpose may simply be to establish a conversation.
This is why traditional awareness advice such as “do not click suspicious links” is increasingly incomplete.
The dangerous action may be replying.
The reply validates the relationship and moves the victim into the next stage of the operation.
Organizations should therefore teach high-risk users to verify unexpected invitations through an independent channel.
If an invitation claims to come from Chatham House, the Atlantic Council, a diplomat, or a known academic, the recipient should verify through a previously known email address, phone number, or official website rather than replying directly to the suspicious message.
The sender domain is another useful clue.
Microsoft notes that Star Blizzard frequently places the impersonated organization’s name in the local part of the email address before the @ symbol, while the actual registered domain belongs to something else.
Users often read the display name and first half of an address while ignoring the domain.
Attackers know this.
Security awareness should teach users to examine the registered domain rather than merely the visible sender name.
On the endpoint side, organizations should hunt for the scheduled-task names observed in the campaign and for unusual tasks created by MSI packages, PowerShell, or document-related processes.
The specific names Microsoft identified are valuable indicators, but defenders should not rely on them exclusively because the attacker can rename them.
The more durable behavior is:
phishing attachment → LNK execution → hidden command shell → MSI download or execution → scheduled-task creation → WebDAV activation → control.exe or remote CPL execution → CosmicPulse installation
That sequence is far more useful for behavioral detection than one task name or hash.
Organizations should also review unnecessary outbound SSH access.
Star Blizzard’s January chain used the legitimate Windows SSH client to retrieve attacker content.
Many enterprise workstations have no operational need to initiate arbitrary outbound SSH connections.
Restricting that traffic can remove an attacker technique without disrupting ordinary user activity in many environments.
Similarly, unusual WebDAV activity deserves attention.
WebDAV allows remote web resources to appear to Windows applications like filesystem paths, which is extremely convenient for legitimate collaboration and equally convenient for attackers trying to make remote malware look local.
Organizations that do not rely on WebDAV should consider restricting or disabling the supporting WebClient functionality.
Phishing-resistant authentication remains important because Star Blizzard continues to conduct credential-stealing operations alongside malware deployment.
Microsoft specifically notes continued use of Evilginx, an adversary-in-the-middle phishing framework capable of stealing authenticated session cookies and bypassing weaker forms of MFA.
FIDO2 security keys and properly implemented passkeys offer substantially better resistance because authentication is cryptographically bound to the legitimate domain.
Ordinary one-time codes do not provide the same protection against real-time phishing proxies.
Another important lesson is log retention.
Microsoft’s published Defender hunting queries may examine only recent telemetry, while these campaigns stretch back months.
Organizations in Star Blizzard’s likely target set should therefore ensure endpoint, identity, email, DNS, proxy, and task-scheduler telemetry is retained long enough to support retrospective investigation.
A seven-day window is not especially helpful when the adversary may have been active since January.
The broader attack chain can be summarized as:
high-value target selected → legitimate-looking invitation sent → victim responds → encrypted archive delivered → LNK disguised as document executed → legitimate Windows tools download MSI → RedFlick scheduled tasks created → WebDAV and Control Panel mechanisms abused → CosmicPulse downloader executed → Python backdoor installed → persistent espionage access established
The notable evolution is the reduction in user interaction and increase in campaign scale.
Star Blizzard has not abandoned social engineering.
It has industrialized more of the process around it.
That is perhaps the most important lesson from Microsoft’s report.
Highly targeted espionage and large-scale phishing used to look like different operational models.
Star Blizzard is increasingly combining them.
The emails can be sent at scale.
The malware delivery can be automated.
The scheduled tasks can handle persistence.
But the lure still feels personal.
For defenders, that creates a difficult combination:
mass distribution with spear-phishing credibility.
The attack may reach hundreds of recipients, but to the individual victim it can still look like a carefully crafted invitation intended specifically for them.
That is exactly the point.
The sophistication is no longer only in the malware.
It is in making scalable espionage still feel personal.

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
Source: Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor via The Hacker News — published 29 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.