Star Blizzard Uses Fake Invites to Install Backdoor

The Hacker News · High sophistication
Last updated September 30, 2026

Microsoft reports Russia-linked Star Blizzard sent fake event invitations and other business notices to trick targets into opening disguised files that install a Windows backdoor. The campaigns targeted Ukraine-linked people and organizations and hit 100+ organizations, mainly in the U.S. and U.K., using multi-step email exchanges and password-protected archives to bypass defenses.

How the attack worked

Star Blizzard's campaigns relied on a slow build rather than an immediate strike. The first email typically carried no attachment at all, functioning purely to start a conversation and establish trust. Only after the target replied did the attacker send a password-protected RAR or ZIP archive, with the password conveniently shown in an image rather than in text. This step alone defeats many automated scanning tools that look for readable passwords or malicious content inside archives.

Inside that archive was a shortcut (LNK) file disguised as a PDF. Opening it triggered a chain that fetched a Windows Installer (MSI), which created scheduled tasks to install the CosmicPulse backdoor. Some March-era replies instead led to a link for an iPhone exploit kit, showing the group adapted its payload depending on the target's device.

Why it succeeded

The lures were built around credible, topical pretexts. Some invitations named well-known think tanks and NGOs, such as Chatham House and the Atlantic Council, as event hosts. Other waves impersonated Ukrainian authorities with fake tax audit and fine notices sent to users of a Ukrainian email service, or used a water shutdown notice aimed at hotels in Kyiv. These pretexts matched the professional context of the targeted policy staff, executive assistants, finance teams, and hotel operations personnel, making the initial emails feel routine rather than suspicious.

The multi-step structure also worked against typical email security controls. Because the first message had no attachment, it passed scanning easily. By the time the archive arrived, the recipient had already replied and was primed to open whatever came next.

What to watch for

  • An email that starts a conversation with no attachment, followed later by a password-protected archive
  • A password delivered only as an image inside the email
  • A file that looks like a PDF but behaves like a shortcut or executable
  • Sender addresses where the real organization's name appears before the @ sign rather than in the domain
  • Unexpected official-sounding notices, such as tax audits or utility outage alerts, that push quick action

Building resistance

Organizations supporting Ukraine-related work, along with policy, NGO, and government staff, should treat reply-triggered attachments as a specific risk category. Encourage staff to verify unexpected invitations or official notices through a phone number or email address they already know, rather than replying directly to the message. Reporting unusual shortcut files or password-protected archives before opening them can stop the chain before the scheduled tasks and backdoor installation occur. Building awareness around these specific mechanics, the reply-then-attach pattern, image-based passwords, and disguised shortcuts, gives staff concrete signals to act on rather than vague suspicion.

Key findings

  • Campaigns used fake event invitations and official-looking notices to start email conversations before delivering malware.
  • Attackers often sent an initial email with no attachment; after a reply, they sent a password-protected RAR/ZIP with the password shown in an image.
  • Payload delivery used a shortcut (LNK) disguised as a PDF, which fetched a Windows Installer (MSI) that created scheduled tasks to install the CosmicPulse backdoor.
  • Invites impersonated well-known think tanks/NGOs (e.g., Chatham House, Atlantic Council) and sometimes appeared to come from inside the target organization.
  • Some March replies led to a link for an iPhone exploit kit (DarkSword) rather than the Windows backdoor.
  • Indicators included domain secure-dns-hub[.]com and IP 103.160.59[.]97; Microsoft noted the domain was still in use at publication time.

Who’s being targeted

  • Commonly targeted roles: Executive leadership, Policy/research teams, Executive assistants, Finance and accounting, Operations and facilities, NGO and government staff supporting Ukraine-related work.
  • Affected industries: Government bodies, NGOs / civil society organizations, Think tanks / policy organizations, Hospitality (hotels), Finance / international financial organizations.
  • Attack channels: email.
  • Impersonated: Atlantic Council (or another well-known think tank/NGO) / internal colleague, Ukrainian authorities, City/utility or facilities-related sender (as presented in the lure).

Red flags to watch for

  • First email has no attachment and tries to start a conversation to build trust
  • Follow-up includes a password-protected archive with the password provided as an image
  • The 'PDF' is actually a shortcut (LNK) disguised as a document
  • Unexpected 'official' penalty/audit notice creates urgency
  • Message is designed to look official but arrives via email without prior case/ticket
  • Attachment/linked document leads to executable behavior rather than a normal PDF
  • Operational disruption bait (service outage) pushes quick action
  • Sender identity may not match the claimed organization (display name vs real domain)
  • Attachment is not a standard document format behavior (passworded archive / shortcut)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did Star Blizzard get malware past email defenses?

The group sent an initial email with no attachment to start a conversation, then followed up with a password-protected RAR or ZIP archive after the target replied, with the password shown in an image so scanners could not read it.

What did the malicious attachment actually look like?

In every case the payload was a shortcut (LNK) file disguised as a PDF, which fetched a Windows Installer that created scheduled tasks to install the CosmicPulse backdoor.

Who was targeted in these campaigns?

Campaigns targeted Ukraine-linked people and organizations, including think tanks, NGOs, government bodies, and hotels in Kyiv, hitting over 100 organizations mostly in the U.S. and U.K.

What are the warning signs of this type of attack?

Watch for emails that build a conversation before sending anything, password-protected archives with an image-based password, PDF-looking files that are actually shortcuts, and sender addresses where the real organization's name appears before the @ sign rather than in the domain.

Read the video transcript

You get this email: “Invitation, Atlantic Council event (details enclosed).” Looks legit, right? That’s exactly how the Star Blizzard backdoor starts. If you reply, they send a password‑protected ZIP or RAR. The password is shown in an image, and inside there’s a so‑called PDF that’s actually a shortcut file, an LNK, that pulls down a Windows installer and plants the CosmicPulse backdoor. They’ve also faked Ukrainian tax audit and fine notices to Ukr.net users, and used domains like secure-dns-hub[.]com that look technical but aren’t official. The pattern is the same: no file at first, then a password‑protected archive and a fake PDF that behaves like a program. Here’s the move: if a “PDF” from an invite or notice comes inside a password‑protected ZIP or RAR, stop. Don’t open it, forward the email to security and let them handle it.

Similar attacks

Star Blizzard Scales Phishing With “RedFlick”

Star Blizzard Scales Phishing With “RedFlick”

Microsoft reports that the Russian state-linked actor Star Blizzard ran large-scale phishing campaigns in 2026 that use convincing lures like tax notices, fines, and “closed-door” event invitations. After a victim replies, the attacker sends a password-protected ZIP/RAR attachment that triggers a…

September 29, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
Fake Claude Download Used in JadeProx Attacks

Fake Claude Download Used in JadeProx Attacks

Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including spear-phishing and a fake software download site. One campaign impersonated Anthropic’s Claude using a lookalike domain to deliver a malicious…

July 23, 2026
Tax and SSA Lures Push Stealth Malware via Cruciferra

Tax and SSA Lures Push Stealth Malware via Cruciferra

Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The campaigns used familiar social-engineering themes, tax documents, U.S. Social Security Administration messages, and even bed-bug complaints,…

July 28, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026