Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.

The Russia-linked threat group Star Blizzard has expanded its cyberespionage operations, targeting more than 100 organizations with fake event invitations and a new malware-delivery technique designed to install the CosmicPulse backdoor on Windows systems.
According to Microsoft Threat Intelligence, the activity has primarily targeted organizations in the United States and United Kingdom, alongside Ukrainian institutions and individuals. Targets include governments, NGOs, think tanks and financial institutions associated with supporting Ukraine.
Campaign at a Glance
| Detail | Information |
|---|---|
| Threat Actor | Star Blizzard |
| Other Names | COLDRIVER, Callisto, SEABORGIUM, TA446 |
| Campaigns Observed | At least 13 large-scale campaigns in 2026 |
| Organizations Affected | 100+ |
| Main Targets | Governments, NGOs, think tanks, financial institutions |
| Delivery Technique | RedFlick |
| Malware | CosmicPulse |
| Primary Method | Spear-phishing / fake event invitations |
Microsoft identifies Star Blizzard as a Russian state threat actor. Western government agencies have previously assessed the group as operating under Center 18 of Russia's Federal Security Service (FSB).
Fake Event Invitations Start the Attack
Star Blizzard frequently begins its attacks with emails impersonating trusted organizations or individuals.
Recent campaigns have used invitations appearing to come from prominent think tanks and NGOs, including themes involving the Atlantic Council and Chatham House.
The first message typically contains no malicious attachment. Instead, attackers attempt to establish a conversation with the target.
If the victim responds, the attackers send a password-protected ZIP or RAR archive containing malicious content.
The attack can be summarized as:
Fake Invitation → Victim Replies → Password-Protected Archive → Malicious LNK → MSI Installer → RedFlick → CosmicPulse
This conversation-based approach can make the phishing attempt appear more credible than an unsolicited email immediately containing malware.
RedFlick Replaces ClickFix
Microsoft says Star Blizzard has shifted from its previous ClickFix-style attacks to a new technique called RedFlick.
Unlike ClickFix, which required victims to manually perform several actions, RedFlick can initiate the malware deployment process after a single user interaction.
A malicious Windows shortcut disguised as a PDF launches the infection chain and retrieves an MSI installer.
In one observed version, the installer created three scheduled tasks:
Internet Quality Test ConnectionNetwork Configuration ManagerSystem Health Monitor
These tasks help establish network connectivity, execute additional payloads and ultimately deploy CosmicPulse.
CosmicPulse Backdoor
The final payload is CosmicPulse, a Python-based backdoor that provides attackers with persistent remote access to compromised Windows systems.
Microsoft says RedFlick uses scheduled tasks and legitimate Windows components such as WebDAV and control.exe during the infection process, helping the activity blend with normal system behavior.
Researchers have also observed Star Blizzard increasingly using email accounts hosted on compromised WordPress and cPanel websites, rather than relying exclusively on newly created accounts from free email providers.
DarkSword Used Against Some iPhone Targets
Not every campaign delivered CosmicPulse.
Microsoft reported that a March campaign using an Atlantic Council-themed lure redirected some targets to DarkSword, an exploit kit targeting Apple iPhones.
This shows Star Blizzard tailoring its payload and exploitation method depending on the target and device.
What Security Teams Should Monitor
Organizations—particularly government bodies, NGOs and think tanks—should monitor for:
- Unexpected password-protected ZIP or RAR attachments
- LNK files disguised as PDFs
- The three suspicious scheduled-task names identified above
- Unexpected outbound SSH connections
- Suspicious WebDAV activity
control.exeloading unusual remote content- Microsoft Defender detections for
Trojan:Script/RedFlick - Microsoft Defender detections for
Backdoor:Python/CosmicPulse
Microsoft also recommends phishing-resistant authentication and appropriate attack-surface-reduction controls to reduce the effectiveness of Star Blizzard's phishing operations.
Security Takeaway
Star Blizzard's latest activity shows a shift from highly targeted spear-phishing toward larger-scale campaigns involving tens or hundreds of emails at a time.
The RedFlick technique also reduces the amount of interaction required from victims:
Trusted-Looking Invitation → Victim Engagement → RedFlick → Scheduled Tasks → CosmicPulse
Microsoft has observed at least 13 large-scale campaigns since January 2026, affecting more than 100 organizations, primarily in the U.S. and U.K.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Researchers uncover malicious Terraform providers and Go modules delivering Graphalgo-linked Go malware using Slack and Ethereum blockchain infrastructure for command and control.


