Star Blizzard Hackers Use Fake Invitations to Install Backdoors
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K.
The group has long stolen email passwords by posing as people its targets know. By 2023, it had already used fake conference and event invitations as bait, often exchanging messages with a target before sending a malicious link.
This year, the group switched to a method called RedFlick, which uses scheduled tasks to install a backdoor named CosmicPulse. The invitations name well-known think tanks or NGOs as hosts, such as Chatham House and the Atlantic Council. Many emails are written to appear to come from within the target's organization.