Skip to main content
The Wire
CyberNews by Zentrya One
Malware

Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor

Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.

The Russia-linked threat group Star Blizzard has expanded its cyberespionage operations, targeting more than 100 organizations with fake event invitations and a new malware-delivery technique designed to install the CosmicPulse backdoor on Windows systems.

According to Microsoft Threat Intelligence, the activity has primarily targeted organizations in the United States and United Kingdom, alongside Ukrainian institutions and individuals. Targets include governments, NGOs, think tanks and financial institutions associated with supporting Ukraine.

Campaign at a Glance

Detail Information
Threat Actor Star Blizzard
Other Names COLDRIVER, Callisto, SEABORGIUM, TA446
Campaigns Observed At least 13 large-scale campaigns in 2026
Organizations Affected 100+
Main Targets Governments, NGOs, think tanks, financial institutions
Delivery Technique RedFlick
Malware CosmicPulse
Primary Method Spear-phishing / fake event invitations

Microsoft identifies Star Blizzard as a Russian state threat actor. Western government agencies have previously assessed the group as operating under Center 18 of Russia's Federal Security Service (FSB).

Fake Event Invitations Start the Attack

Star Blizzard frequently begins its attacks with emails impersonating trusted organizations or individuals.

Recent campaigns have used invitations appearing to come from prominent think tanks and NGOs, including themes involving the Atlantic Council and Chatham House.

The first message typically contains no malicious attachment. Instead, attackers attempt to establish a conversation with the target.

If the victim responds, the attackers send a password-protected ZIP or RAR archive containing malicious content.

The attack can be summarized as:

Fake Invitation → Victim Replies → Password-Protected Archive → Malicious LNK → MSI Installer → RedFlick → CosmicPulse

This conversation-based approach can make the phishing attempt appear more credible than an unsolicited email immediately containing malware.

RedFlick Replaces ClickFix

Microsoft says Star Blizzard has shifted from its previous ClickFix-style attacks to a new technique called RedFlick.

Unlike ClickFix, which required victims to manually perform several actions, RedFlick can initiate the malware deployment process after a single user interaction.

A malicious Windows shortcut disguised as a PDF launches the infection chain and retrieves an MSI installer.

In one observed version, the installer created three scheduled tasks:

  • Internet Quality Test Connection
  • Network Configuration Manager
  • System Health Monitor

These tasks help establish network connectivity, execute additional payloads and ultimately deploy CosmicPulse.

CosmicPulse Backdoor

The final payload is CosmicPulse, a Python-based backdoor that provides attackers with persistent remote access to compromised Windows systems.

Microsoft says RedFlick uses scheduled tasks and legitimate Windows components such as WebDAV and control.exe during the infection process, helping the activity blend with normal system behavior.

Researchers have also observed Star Blizzard increasingly using email accounts hosted on compromised WordPress and cPanel websites, rather than relying exclusively on newly created accounts from free email providers.

DarkSword Used Against Some iPhone Targets

Not every campaign delivered CosmicPulse.

Microsoft reported that a March campaign using an Atlantic Council-themed lure redirected some targets to DarkSword, an exploit kit targeting Apple iPhones.

This shows Star Blizzard tailoring its payload and exploitation method depending on the target and device.

What Security Teams Should Monitor

Organizations—particularly government bodies, NGOs and think tanks—should monitor for:

  • Unexpected password-protected ZIP or RAR attachments
  • LNK files disguised as PDFs
  • The three suspicious scheduled-task names identified above
  • Unexpected outbound SSH connections
  • Suspicious WebDAV activity
  • control.exe loading unusual remote content
  • Microsoft Defender detections for Trojan:Script/RedFlick
  • Microsoft Defender detections for Backdoor:Python/CosmicPulse

Microsoft also recommends phishing-resistant authentication and appropriate attack-surface-reduction controls to reduce the effectiveness of Star Blizzard's phishing operations.

Security Takeaway

Star Blizzard's latest activity shows a shift from highly targeted spear-phishing toward larger-scale campaigns involving tens or hundreds of emails at a time.

The RedFlick technique also reduces the amount of interaction required from victims:

Trusted-Looking Invitation → Victim Engagement → RedFlick → Scheduled Tasks → CosmicPulse

Microsoft has observed at least 13 large-scale campaigns since January 2026, affecting more than 100 organizations, primarily in the U.S. and U.K.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.