Threat Intelligence

Russian State Hackers Use Fake Event Invites to Plant Backdoor on Windows PCs

The Hacker News · 30 Sept 2026
Key Takeaway Be wary of unsolicited event or conference invitations, especially those requiring a password-protected file to open, and verify unexpected requests through a separate, known contact channel.

Microsoft has revealed that Star Blizzard, a Russian state-backed hacking group linked to the FSB, has run more than a dozen large phishing campaigns this year using fake invitations to conferences hosted by well-known think tanks and NGOs, such as Chatham House and the Atlantic Council. The campaigns have affected over 100 organizations, mostly in the US and UK, and are aimed at people and groups connected to Ukraine.

The attackers typically send an email without an attachment first, then follow up with a password-protected archive if the target replies, with the password shown as an image to avoid automated scanning. Since March, the group has used hacked WordPress and cPanel email accounts rather than free services, making the messages appear more legitimate. Techniques have evolved throughout the year, from fake CAPTCHA pages that trick victims into running commands themselves, to a newer method called RedFlick that uses Windows scheduled tasks to quietly install a backdoor named CosmicPulse. In one case, victims were redirected to an iPhone exploit kit instead of the usual Windows malware.

Earlier lures impersonated Ukrainian tax authorities and utility providers, and one targeted staff at an international financial organization with a fake payment notice. The consistent theme is a trusted-sounding invitation designed to start a conversation before the malicious payload is delivered.

phishing state-sponsored backdoor Star Blizzard Windows security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.