Thehackernews iconThehackernewsSep 29, 2026 ~7 min source read

Star Blizzard used fake event invites and a new ‘RedFlick’ method to install the CosmicPulse backdoor

Microsoft says Russia-linked group Star Blizzard sent realistic event invitations to people and organizations tied to Ukraine, then used shortcut files and MSI installers to create scheduled tasks that fetch a Python backdoor named CosmicPulse.

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Share this story

Send the public story page.

Useful takeaways from this story.

Star Blizzard sent password-protected archives and malicious links in reply chains to more than 100 organizations tied to Ukraine since January 2026.

The group’s RedFlick technique uses LNK shortcuts and MSI packages to create scheduled tasks that download and run the CosmicPulse backdoor.

Defensive steps include checking sender domains, hunting for three specific scheduled-task names, and blocking known indicators Microsoft published.

What Star Blizzard sent and why it looked convincing

  • If the recipient replied, attackers sent a password-protected RAR or ZIP file. The archive password was presented inside an image to defeat simple automated scanning.
  • The MSI created three scheduled tasks with names designed to look like ordinary network components: Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor.
  • The next-stage component masqueraded as a Control Panel item and installed CosmicPulse, a Python-based backdoor (formerly reported with names such as NOROBOT or BAITSWITCH).

Technique evolution and infrastructure

Microsoft calls the 2026 installation approach RedFlick. Earlier Star Blizzard methods used free consumer email services and, in 2025, fake CAPTCHA pages (ClickFix) that tricked users into running commands. In 2026, Microsoft saw at least 13 larger RedFlick campaigns plus routine targeted phishing. Since March, campaigns increasingly used email accounts on WordPress and cPanel sites Microsoft believes were hacked for this purpose.

Microsoft and other reporting note overlap between RedFlick activity and a June campaign targeting Ukrainian civil society groups (reported by Digital Security Lab Ukraine). Two overlapping indicators are IP 103.160.59[.]97 and domain secure-dns-hub[.]com. Microsoft left secure-dns-hub[.]com active in its indicators at publication time (September 29, 2026).

Recipients are people and organizations tied to Ukraine policy, reconstruction, civil society, and international affairs. Named lures included fake tax audit notices to Ukr.net users, hotel water-shutdown notices in Kyiv, and payment notices for staff of an international financial organization.

Microsoft published hunting queries and indicators. Practical checks for organizations Microsoft identified as likely targets:

  • Search endpoints for the three scheduled tasks named above.
  • Block or monitor the specific indicators Microsoft published, including secure-dns-hub[.]com and the IP noted in reporting.

Star Blizzard shifted techniques to a scheduled-task–based installation chain (RedFlick) to install CosmicPulse. The social engineering used realistic event invitations and reply-based escalation, increasing the chance that targets would open attachments or follow links. Organizations working on Ukraine-related policy or assistance should prioritize sender verification and the specific artifact hunts Microsoft recommended.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app