Microsoft reports Russia-linked Star Blizzard sent fake event invitations and other business notices to trick targets into opening disguised files that install a Windows backdoor. The campaigns targeted Ukraine-linked people and organizations and hit 100+ organizations, mainly in the U.S. and U.K., using multi-step email exchanges and password-protected archives to bypass defenses.
How the attack worked
Star Blizzard's campaigns relied on a slow build rather than an immediate strike. The first email typically carried no attachment at all, functioning purely to start a conversation and establish trust. Only after the target replied did the attacker send a password-protected RAR or ZIP archive, with the password conveniently shown in an image rather than in text. This step alone defeats many automated scanning tools that look for readable passwords or malicious content inside archives.
Inside that archive was a shortcut (LNK) file disguised as a PDF. Opening it triggered a chain that fetched a Windows Installer (MSI), which created scheduled tasks to install the CosmicPulse backdoor. Some March-era replies instead led to a link for an iPhone exploit kit, showing the group adapted its payload depending on the target's device.
Why it succeeded
The lures were built around credible, topical pretexts. Some invitations named well-known think tanks and NGOs, such as Chatham House and the Atlantic Council, as event hosts. Other waves impersonated Ukrainian authorities with fake tax audit and fine notices sent to users of a Ukrainian email service, or used a water shutdown notice aimed at hotels in Kyiv. These pretexts matched the professional context of the targeted policy staff, executive assistants, finance teams, and hotel operations personnel, making the initial emails feel routine rather than suspicious.
The multi-step structure also worked against typical email security controls. Because the first message had no attachment, it passed scanning easily. By the time the archive arrived, the recipient had already replied and was primed to open whatever came next.
What to watch for
- An email that starts a conversation with no attachment, followed later by a password-protected archive
- A password delivered only as an image inside the email
- A file that looks like a PDF but behaves like a shortcut or executable
- Sender addresses where the real organization's name appears before the @ sign rather than in the domain
- Unexpected official-sounding notices, such as tax audits or utility outage alerts, that push quick action
Building resistance
Organizations supporting Ukraine-related work, along with policy, NGO, and government staff, should treat reply-triggered attachments as a specific risk category. Encourage staff to verify unexpected invitations or official notices through a phone number or email address they already know, rather than replying directly to the message. Reporting unusual shortcut files or password-protected archives before opening them can stop the chain before the scheduled tasks and backdoor installation occur. Building awareness around these specific mechanics, the reply-then-attach pattern, image-based passwords, and disguised shortcuts, gives staff concrete signals to act on rather than vague suspicion.
Key findings
- Campaigns used fake event invitations and official-looking notices to start email conversations before delivering malware.
- Attackers often sent an initial email with no attachment; after a reply, they sent a password-protected RAR/ZIP with the password shown in an image.
- Payload delivery used a shortcut (LNK) disguised as a PDF, which fetched a Windows Installer (MSI) that created scheduled tasks to install the CosmicPulse backdoor.
- Invites impersonated well-known think tanks/NGOs (e.g., Chatham House, Atlantic Council) and sometimes appeared to come from inside the target organization.
- Some March replies led to a link for an iPhone exploit kit (DarkSword) rather than the Windows backdoor.
- Indicators included domain secure-dns-hub[.]com and IP 103.160.59[.]97; Microsoft noted the domain was still in use at publication time.
Who’s being targeted
- Commonly targeted roles: Executive leadership, Policy/research teams, Executive assistants, Finance and accounting, Operations and facilities, NGO and government staff supporting Ukraine-related work.
- Affected industries: Government bodies, NGOs / civil society organizations, Think tanks / policy organizations, Hospitality (hotels), Finance / international financial organizations.
- Attack channels: email.
- Impersonated: Atlantic Council (or another well-known think tank/NGO) / internal colleague, Ukrainian authorities, City/utility or facilities-related sender (as presented in the lure).
Red flags to watch for
- First email has no attachment and tries to start a conversation to build trust
- Follow-up includes a password-protected archive with the password provided as an image
- The 'PDF' is actually a shortcut (LNK) disguised as a document
- Unexpected 'official' penalty/audit notice creates urgency
- Message is designed to look official but arrives via email without prior case/ticket
- Attachment/linked document leads to executable behavior rather than a normal PDF
- Operational disruption bait (service outage) pushes quick action
- Sender identity may not match the claimed organization (display name vs real domain)
- Attachment is not a standard document format behavior (passworded archive / shortcut)
Frequently asked questions
How did Star Blizzard get malware past email defenses?
The group sent an initial email with no attachment to start a conversation, then followed up with a password-protected RAR or ZIP archive after the target replied, with the password shown in an image so scanners could not read it.
What did the malicious attachment actually look like?
In every case the payload was a shortcut (LNK) file disguised as a PDF, which fetched a Windows Installer that created scheduled tasks to install the CosmicPulse backdoor.
Who was targeted in these campaigns?
Campaigns targeted Ukraine-linked people and organizations, including think tanks, NGOs, government bodies, and hotels in Kyiv, hitting over 100 organizations mostly in the U.S. and U.K.
What are the warning signs of this type of attack?
Watch for emails that build a conversation before sending anything, password-protected archives with an image-based password, PDF-looking files that are actually shortcuts, and sender addresses where the real organization's name appears before the @ sign rather than in the domain.
Read the video transcript
You get this email: “Invitation, Atlantic Council event (details enclosed).” Looks legit, right? That’s exactly how the Star Blizzard backdoor starts. If you reply, they send a password‑protected ZIP or RAR. The password is shown in an image, and inside there’s a so‑called PDF that’s actually a shortcut file, an LNK, that pulls down a Windows installer and plants the CosmicPulse backdoor. They’ve also faked Ukrainian tax audit and fine notices to Ukr.net users, and used domains like secure-dns-hub[.]com that look technical but aren’t official. The pattern is the same: no file at first, then a password‑protected archive and a fake PDF that behaves like a program. Here’s the move: if a “PDF” from an invite or notice comes inside a password‑protected ZIP or RAR, stop. Don’t open it, forward the email to security and let them handle it.