Microsoft Says Star Blizzard Used Fake Event Invitations to Deliver CosmicPulse Backdoor

Threat intelligence analysts tracing a spear-phishing campaign using fake event invitations

Microsoft Threat Intelligence says the Russia-linked actor Star Blizzard has refined its phishing and malware delivery operations with a technique the company calls RedFlick. The group used fake invitations and follow-up correspondence to persuade selected targets to open password-protected archives that ultimately installed a backdoor named CosmicPulse.

The campaign blended social engineering with scheduled execution

Microsoft identified at least 13 larger campaigns during 2026, in addition to more narrowly targeted activity. The emails impersonated recognized organizations and event hosts, while compromised WordPress and cPanel webmail accounts helped make messages appear more credible. The archive password was presented separately, encouraging recipients to treat the file as protected material.

After execution, RedFlick used scheduled tasks to establish persistence and launch CosmicPulse. Microsoft said the activity focused heavily on organizations and individuals connected to Ukraine, policy research and international affairs.

Defenders should investigate the conversation, not only the attachment

Security teams should review multi-message exchanges, unusual password-protected archives and new scheduled tasks together. Compromised third-party mailboxes can defeat simple sender-reputation checks, so identity telemetry and endpoint evidence remain essential. SectechMedia tracks related campaigns in its cybersecurity coverage.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *