Full Report
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
Analysis Summary
# Threat Actor: Star Blizzard
## Attribution & Identity
* **Actor Identification:** Star Blizzard is a Russian state-sponsored threat group.
* **Aliases:** ColdRiver, TA446.
* **Known Associations:** Highly confident attribution to **Center 18 of Russia's Federal Security Service (FSB)**, as identified by security agencies in the U.S., U.K., Australia, Canada, and New Zealand.
## Activity Summary
Since January 2026, the group has executed at least 13 large-scale campaigns affecting over 100 organizations. Notable activity includes:
* **Phishing Operations:** Using fake event invitations (e.g., Atlantic Council, Chatham House) to deliver backdoors.
* **Infrastructure Shift:** Transitioning from free email services (Proton, Microsoft) to compromised WordPress and cPanel accounts for sending phishing emails.
* **Multi-Platform Targeting:** Deployment of a Windows backdoor (CosmicPulse) and an iPhone exploit kit (DarkSword).
## Tactics, Techniques & Procedures
* **Social Engineering:** Posing as known contacts, think tanks, or NGOs. Using password-protected ZIP/RAR archives where the password is provided via an image to evade automated scanning.
* **Multi-Stage Infection:**
* Initial lures often contain no attachments to build trust.
* LNK files disguised as PDFs trigger background commands.
* Windows Installer (MSI) packages used to establish persistence.
* **Persistence & Execution:**
* **Scheduled Tasks:** Creating tasks named "Internet Quality Test Connection," "Network Configuration Manager," and "System Health Monitor" to blend in.
* **Abuse of Living-off-the-Land Binaries (LoLBins):** Using `control.exe` to execute malicious code.
* **WebDAV:** Leveraging WebDAV to treat remote C2 folders as local directories.
* **Execution Techniques:**
* **ClickFix:** Tricking users into running commands via fake CAPTCHA pages.
* **RedFlick:** A refined technique using scheduled tasks to install backdoors.
* **MITRE ATT&CK Mapping (Inferred):**
* T1566.001 (Phishing: Spearphishing Attachment)
* T1053.005 (Scheduled Task/Job: Scheduled Task)
* T1204.002 (User Execution: Malicious File)
* T1218.011 (System Binary Proxy Execution: Control Panel)
## Targeting
* **Sectors:** Think tanks, NGOs, international financial organizations, government agencies (Ukrainian authorities), and hotels.
* **Geography:** Primarily United Kingdom and United States; significant targeting of individuals and organizations tied to Ukraine.
* **Victims:** Users of the Ukrainian email service Ukr.net; staff at the Atlantic Council and Chatham House.
## Tools & Infrastructure
* **Malware:**
* **CosmicPulse:** A Python-based backdoor.
* **DarkSword:** An iPhone exploit kit.
* **NOROBOT / BAITSWITCH:** A downloader disguised as a Control Panel item.
* **Infrastructure:**
* Compromised WordPress and cPanel websites for email delivery.
* C2 servers facilitating WebDAV connections.
* Use of SSH for malicious downloads in early 2026 campaigns.
## Implications
Star Blizzard represents a persistent and evolving espionage threat. Their transition from simple credential harvesting to sophisticated multi-stage malware delivery (RedFlick) and mobile exploitation (DarkSword) indicates an increased technical capability. Their focus on high-profile think tanks and organizations tied to Ukraine highlights a strategic objective to gain intelligence on Western foreign policy and geopolitical support for Ukraine.
## Mitigations
* **Email Security:** Implement advanced phishing protection that can scan password-protected archives and OCR images for embedded passwords.
* **Endpoint Monitoring:** Monitor for suspicious creation of Windows Scheduled Tasks, particularly those involving `control.exe` or referencing unusual remote WebDAV paths.
* **User Training:** Educate staff on "ClickFix" tactics and the dangers of running commands from web pages or opening unexpected LNK/PDF files.
* **Network Defense:** Restrict outbound SSH and WebDAV traffic to known-good destinations; block access to newly registered or suspicious WordPress/cPanel-hosted domains used for mail.