More than 100 organizations have been targeted since January, mostly in the U.S. and U.K., in a sustained phishing campaign that uses fake event invitations to deliver a Windows backdoor, Microsoft reported on September 29.
Scope and the actors Microsoft and allies point to
Microsoft says the campaigns are aimed at people and organizations tied to Ukraine and have run in dozens of waves this year. Security agencies in the U.S., U.K., Australia, Canada and New Zealand said in December 2023 that the group known as Star Blizzard “almost certainly” works under Center 18 of Russia’s Federal Security Service (FSB). Microsoft counted at least 13 larger campaigns in 2026, each sending tens to hundreds of emails on top of Star Blizzard’s usual targeted phishing; at least one computer was confirmed infected, though Microsoft did not disclose the total number of breached organizations.
How the intrusion chain operates: LNK to MSI to scheduled tasks
Microsoft traced several consistent stages in the attacks. A shortcut file (LNK) disguised as a PDF is the initial trigger. Opening that shortcut runs quiet commands that fetch a Windows Installer (MSI) package from a remote server. The MSI then sets up scheduled tasks that persist and stage further activity.
Versions differ by month. In January the hidden script used the SSH program to download the installer; in July the shortcut first downloaded a PDF that hid a command intended to fetch the installer. In April Microsoft observed the installer create three scheduled tasks named to look like benign components:
- Internet Quality Test Connection
- Network Configuration Manager
- System Health Monitor
Microsoft says the first task can send the computer name and user name to the attackers’ command-and-control server and run additional remote code. The second creates a WebDAV mapping so a web address appears as a folder. The third uses control.exe (the Windows Control Panel program) to run the next stage from the C2 server.
The next-stage payload is a downloader disguised as a Control Panel item that installs CosmicPulse, a Python-based backdoor. Microsoft notes that earlier names for this downloader include NOROBOT and BAITSWITCH. The technique Microsoft calls RedFlick deploys scheduled tasks to install CosmicPulse; in 2025 the group used a different trick—fake CAPTCHA pages Microsoft calls ClickFix—to trick targets into running commands themselves.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDelivery, lures, and overlapping reporting from other defenders
Star Blizzard’s principal bait this year has been fake event invitations that name well-known think tanks or NGOs—Microsoft cited Chatham House and the Atlantic Council as examples—and many emails are crafted to look as if they come from inside the target’s organization. Typically the first message contains no attachment; if a target replies, the attackers send a password-protected RAR or ZIP with the password provided in an image.
Earlier lures impersonated Ukrainian authorities, including fake tax-audit and fine notices directed at Ukr.net users in January and February. Later lures included a water-shutdown notice for hotels in Kyiv and a payment notice for staff at an international financial organization.
Not every bait followed the Windows-backdoor path. Microsoft said one March Atlantic Council-themed thread led targets to DarkSword, an iPhone exploit kit. Proofpoint reported Atlantic Council-themed emails in March and a sharp rise in the group’s email volume. Trellix observed related messages and judged the link to DarkSword with medium confidence because the exploit pages were offline and code was not recovered.
Since March, Microsoft says, the group has increasingly used email accounts on hacked WordPress and cPanel sites rather than the free Proton and Microsoft consumer accounts it used earlier. Microsoft also notes two indicators shared with a June campaign reported by Digital Security Lab Ukraine—IP 103.160.59[.]97 and domain secure-dns-hub[.]com—but cautions that sharing indicators does not by itself prove the same actor ran both campaigns. When Microsoft published its report on September 29, secure-dns-hub[.]com remained in use.
How think tanks, NGOs, and government bodies should act now
- Check sender addresses carefully: in these campaigns Microsoft found the real organization’s name in the local-part (before the @) rather than in the domain; when in doubt, verify via a known phone number or email address.
- Search for the three scheduled-task names above and for Microsoft Defender detections Trojan:Script/RedFlick and Backdoor:Python/CosmicPulse.
- Broaden Defender XDR hunting windows. Microsoft’s published Defender queries look back seven days; Defender’s advanced hunting can retain up to 30 days of raw data and organizations may need longer log retention (for example in Microsoft Sentinel) to examine activity back to January.
- Limit or block outbound SSH where it is not required—Microsoft saw SSH used in the January variant to fetch the installer.
- If using Microsoft Defender, enable attack-surface reduction rules that block rare or untrusted executables and obfuscated scripts. Defender XDR customers can consult Microsoft’s threat analytics reports for recommended response actions; Microsoft’s public report does not list specific cleanup steps for a machine where the tasks are found.
- Address mobile risk: Trellix advises updating iPhones to iOS 26.3 or later (which it says fixes the six DarkSword flaws) and enabling Lockdown Mode where needed.
- Move to phishing-resistant sign-in methods: Microsoft warns Star Blizzard still uses password phishing with tools such as Evilginx that can capture session cookies and bypass two-factor defenses.
Conclusion
Microsoft’s account describes an actor that has shifted tools repeatedly—provisioning hacked web accounts, switching from ClickFix to RedFlick, and using scheduled tasks and WebDAV to hide a Python backdoor—while continuing to refine social engineering with trusted-looking event invites. For the NGOs, think tanks, and government offices named and implied in the lures, the technical details Microsoft published point to two practical realities: the intrusion vector is human first (replying to a deceptively normal invitation) and the persistence mechanism is a set of Windows-native features defenders can hunt for. The question the report leaves plainly visible is operational: will those targeted organizations expand hunting and log retention to follow months-long campaign rhythms and disrupt the scheduled tasks and C2 domains that Microsoft identifies?




