Ethical Hacking News
A sophisticated nation-state sponsored hacking group, known as Star Blizzard, has been targeting organizations in the United States and the United Kingdom with fake event invitations, aiming to deliver a backdoor on their Windows computers. The group, believed to be affiliated with the Russian Federal Security Service (FSB), has affected over 100 organizations since January, with at least one computer reportedly infected. To protect against this attack, organizations are advised to take proactive measures to stay vigilant and secure their networks.
Over 100 organizations in the US and UK have been targeted with fake event invitations by the Star Blizzard group. The group, believed to be affiliated with the Russian FSB, has been using fake invitations to deliver a sophisticated backdoor on Windows computers. The backdoor allows attackers to gain remote access to the compromised computer. The group has used various techniques to evade detection, including CAPTCHA pages and malware delivery through email accounts on WordPress and cPanel websites. Security agencies have confirmed that the Star Blizzard group is affiliated with Center 18 of the Russian FSB. Organizations can protect themselves by checking sender addresses, blocking SSH connections, and using phishing-resistant sign-in methods.
In a worrying trend, the nation-state sponsored hacking group, known as Star Blizzard, has been actively targeting organizations in the United States and the United Kingdom with fake event invitations, aiming to deliver a sophisticated backdoor on their Windows computers. According to recent reports, this malicious campaign has affected over 100 organizations since January, with at least one computer reportedly infected.
The Star Blizzard group, which is believed to be affiliated with the Russian Federal Security Service (FSB), has been using fake event invitations as bait to trick targets into installing the backdoor on their computers. The invitations, which appear to be from reputable organizations such as Chatham House and the Atlantic Council, are designed to appear legitimate and build trust with the target.
Once the target replies to the invitation, the group sends a password-protected RAR or ZIP archive, with the password shown in an image. This archive contains a shortcut (LNK) file disguised as a PDF, which initiates the attack and downloads a Windows Installer (MSI) package from a remote server. The MSI package sets up scheduled tasks, which can run commands that fetch the installer from a remote server.
In the version seen in April, the installer created three scheduled tasks named to look like normal network components, including "Internet Quality Test Connection," "Network Configuration Manager," and "System Health Monitor." These tasks send the computer name and user name to the group's command-and-control (C2) server and can run more code from a remote location.
The next stage of the attack is a downloader disguised as a Control Panel item, which installs a Python-based backdoor named CosmicPulse. This backdoor is believed to provide the attackers with remote access to the compromised computer.
Microsoft has reported that the Star Blizzard group has used a variety of techniques to evade detection, including fake CAPTCHA pages, ClickFix, and RedFlick. The group has also been using email accounts on WordPress and cPanel websites to deliver their malware.
The invitations name well-known think tanks or NGOs as hosts, and many emails are written to appear to come from within the target's organization. The group has also been using the SSH program to download the installer.
Security agencies in the United States, the United Kingdom, Australia, Canada, and New Zealand have confirmed that the Star Blizzard group is almost certainly affiliated with Center 18 of the Russian Federal Security Service (FSB).
To protect against this attack, organizations are advised to check sender addresses, search for the three scheduled task names mentioned above, and block or limit outbound SSH connections. They are also advised to turn on attack surface reduction rules that block rare, new, or untrusted executable files and obfuscated scripts.
In addition, organizations are advised to use phishing-resistant sign-in methods, update their iPhones to the latest version, and turn on Lockdown Mode. Microsoft's public report also provides recommended response actions for a computer where the tasks are found.
Overall, the Star Blizzard campaign highlights the sophistication and creativity of nation-state sponsored hacking groups and the importance of staying vigilant and taking proactive measures to protect against these types of attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Russias-Star-Blizzard-Campaign-A-Sophisticated-Nation-State-Attack-on-100-Organizations-ehn.shtml
https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
Published: Tue Sep 29 14:47:05 2026 by llama3.2 3B Q4_K_M