Star Blizzard Phishing Uses Fake Invites

The Hacker News · High sophistication
Last updated October 6, 2026

The recap describes a real phishing operation by the Russia-linked group Star Blizzard, which used email “invitations” to trick targets into engaging and then opening a password-protected archive. The approach is designed to reduce friction, only one click/open action is needed, making it easier for busy people to fall for it.

How the Attack Worked

This campaign relied on a two-stage phishing approach. The first email masqueraded as an invitation, designed to start a conversation and build enough trust that the recipient would reply. Once a target responded, Star Blizzard sent a follow-up message containing a password-protected archive. Opening that archive triggered the infection chain, which was built to deploy a custom backdoor through scheduled tasks set up via the RedFlick technique.

What makes this flow notable is its simplicity from the attacker's perspective. Rather than requiring multiple clicks, downloads, or credential entries, the infection only needed a single user interaction, opening the archive, to succeed. That single-action design reduces friction in the compromise process and increases the odds that a distracted or busy employee will complete the step without pausing to question it.

Why It Succeeded

The invitation pretext works because it taps into ordinary professional behavior. Executives, executive assistants, and policy or international program staff regularly receive invitations to events, meetings, and conferences as part of their normal workload. An email that looks like one more invitation does not immediately stand out as suspicious, especially when it does not ask for anything unusual on the first contact.

The follow-up password-protected archive adds another layer of success for the attacker. Because the file is encrypted, many security scanners cannot inspect its contents before delivery, and the victim has already been primed to expect something related to the invitation they responded to. This sequencing, invitation first, payload second, lowers suspicion at each step rather than asking for everything at once.

What to Watch For

  • Unexpected invitation emails that try to start a conversation before revealing any real content or attachment
  • A follow-up message that arrives only after a reply, containing a password-protected archive
  • Pressure to take one quick action, like opening an archive, to see event details or confirm participation
  • Any workflow that feels unusually simple or frictionless for something involving an unfamiliar sender

Building Resistance

Organizations in government, NGOs, think tanks, and policy-focused education settings should treat unsolicited invitation emails with the same scrutiny as any other unexpected request. Verifying the sender through a trusted channel before replying or opening any attachment is a reasonable baseline step, particularly for staff who regularly interact with external partners and event organizers.

Teams should also recognize that password-protected archives are commonly used to conceal malicious content from automated scanning, so their presence in an unsolicited email deserves extra caution regardless of how legitimate the surrounding conversation appears. Finally, awareness training should emphasize that a workflow requiring only a single action is not automatically safer; many modern attacks are deliberately designed to succeed with minimal user interaction, which is exactly what made this RedFlick infection chain effective against its targets.

Key findings

  • Star Blizzard used phishing emails disguised as “invitations” to start the interaction and then sent a follow-up with a password-protected archive.
  • The infection flow was changed to require only a single user interaction, lowering the barrier to compromise.
  • Targets included Ukrainian individuals and institutions plus international NGOs, think tanks, and governments tied to international policy.

Who’s being targeted

  • Commonly targeted roles: Executives, Executive assistants, Public affairs / communications, Policy / international programs, NGO staff, Government staff.
  • Affected industries: Government, Nonprofits/NGOs, Think tanks / policy organizations, Education (universities).
  • Attack channels: email.
  • Impersonated: An events organizer or partner organization sending an invitation.

Red flags to watch for

  • Unexpected invitation email that tries to start a conversation first
  • Follow-up message includes a password-protected archive
  • Pressure to take a single quick action (open the archive) to view details
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Star Blizzard invitation phishing technique?

Star Blizzard sends phishing emails disguised as invitations to start a conversation, then follows up with a password-protected archive that triggers malware once opened.

Why are password-protected archives dangerous in phishing emails?

Password-protected archives can hide malicious content from email security scanners, and in this campaign they were used to trigger the infection chain once opened.

Who was targeted by this Star Blizzard campaign?

Targets included Ukrainian individuals and institutions, along with international NGOs, think tanks, and governments involved in international policy.

Why is a single-click infection flow more dangerous?

Reducing the attack to one user action, like opening an archive, lowers the barrier to compromise and makes it easier for busy or distracted people to fall for it.

Read the video transcript

You get an email: subject line just says “Invitation.” Looks like a partner org inviting you to an event. Behind the scenes, this is Star Blizzard using a technique called RedFlick. Once you reply, they send a password‑protected archive that silently kicks off malware called CosmicPulse. Here’s the trick: the whole RedFlick attack only needs one quick action from you, open that archive. One click, and they’ve got a backdoor into your system. If you get an unexpected invitation that comes with a password‑protected archive, stop. Call or message the supposed sender on a trusted channel before you open anything.

Similar attacks

Spoofed Portal Drops APT36 Backdoor on Telecoms

Spoofed Portal Drops APT36 Backdoor on Telecoms

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to…

August 18, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
Star Blizzard Scales Phishing With “RedFlick”

Star Blizzard Scales Phishing With “RedFlick”

Microsoft reports that the Russia-linked group Star Blizzard expanded from highly targeted spear-phishing to larger email campaigns aimed at Ukraine supporters globally. Lures included tax-audit/unpaid-fine notices and fake conference invitations, followed by a password-protected archive that…

September 30, 2026