Image: The Hacker News
More than 100 organizations linked to Ukraine have received fake event invitations from Russia-aligned Star Blizzard since January, according to Microsoft. Most targets were in the U.S. and U.K.; at least one Windows computer was infected, but the total number of breached organizations is unknown.
Treat follow-up archives with caution
The Hacker News reports that the first email usually contains no attachment. If the recipient replies, the attackers send a password-protected RAR or ZIP archive, with its password displayed in an image.The messages impersonate prominent think tanks and NGOs, including Chatham House and the Atlantic Council. Some are written to look like internal emails from the recipient’s own organization.
- Check the full sender address: in these campaigns, the genuine organization’s name may appear before the @ sign rather than as the email domain.
- Confirm unexpected invitations through a phone number or email address you already trust, especially before opening an archive.
A fake PDF starts the Windows infection
Microsoft traced several versions of the attack, all beginning with a Windows shortcut file disguised as a PDF. Opening it downloads a Windows Installer package, which creates scheduled tasks—jobs Windows runs automatically—and ultimately installs the Python-based CosmicPulse backdoor.Checks for targeted organizations
Government bodies, NGOs and think tanks working on Ukraine policy should search Windows systems for the scheduled tasks “Internet Quality Test Connection,” “Network Configuration Manager” and “System Health Monitor.” Microsoft Defender may identify the activity as Trojan:Script/RedFlick or BackdoorOrganizations can also check logs and security tools for secure-dns-hub[.]com and 103.160.59[.]97. These indicators appeared in Microsoft’s list and an earlier Ukrainian campaign report, although that overlap alone does not prove both operations had the same attacker.
- If any listed task or Defender detection appears, isolate the computer and have the security team investigate rather than deleting the task alone.
- Microsoft Defender XDR customers can consult its threat analytics reports for recommended response actions; the public report did not provide specific cleanup instructions.