The news
Star Blizzard, a hacking group Microsoft (MSFT) attributes to a unit of Russia's FSB security service, sent fake event invitations and other lures that affected more than 100 organizations, mostly in the US and UK, between January and August 2026, Microsoft said on September 29.
Microsoft said it observed at least 13 distinct large-scale phishing campaigns aimed mainly at nongovernmental organizations, think tanks and government bodies. Targets included officials, international financial institutions, researchers, academics, journalists and diplomats, particularly those supporting Ukraine. Microsoft said the campaigns ran at a scale not previously seen from the group, with tens to hundreds of emails each, CyberScoop reported.
The emails invited recipients to events that appeared to be hosted by well-known policy groups, including the International Institute for Strategic Studies, the Atlantic Council, Chatham House and the US-Ukraine Business Council. Other lures were fake tax audits, fines and payment notices, CyberScoop reported. Senders impersonated political and diplomatic figures, and the real organization's name appeared only in the part of the email address before the @ sign, not in the domain. Microsoft said the group sent the messages from accounts it created on compromised WordPress and cPanel websites, rather than the free email services it used before.
The trap needed patience from the attackers. The first email carried no attachment. If the target replied, a follow-up arrived with a password-protected RAR or ZIP archive, the password shown as an image. Inside was a shortcut file disguised as a PDF. Opening it launched a Windows installer that set up scheduled tasks and deployed CosmicPulse, a backdoor written in Python. Microsoft calls the delivery technique RedFlick and says it needs only a single user interaction.
The earliest campaigns, in January and February, targeted users of the Ukrainian email provider Ukr.net, and the group expanded beyond Ukraine starting in March, Microsoft said. Microsoft has not said how many targets were compromised; it said it notifies customers that have been targeted or compromised directly. The Hacker News reported that at least one computer was infected.
The numbers
- Organizations affected (Microsoft)
- More than 100
- Distinct large-scale campaigns observed (Microsoft)
- At least 13
- Emails per campaign (Microsoft, via CyberScoop)
- Tens to hundreds
- Campaign period covered
- January to August 2026
Why CEOs should care
Any company that works on Ukraine, security policy, international finance or government affairs should assume its executives are in scope. The lure is an ordinary part of a leader's week: an invitation to a roundtable or conference from a respected institution. Set a simple rule for executives and the assistants who manage their calendars: confirm any unexpected invitation by contacting the organizer through a phone number or address you already have, and never open a password-protected file that arrives after replying to an invite. No legitimate event requires it.
CISOs should tune defenses to this exact chain. Quarantine password-protected archives from outside senders by default, block shortcut files inside archives, and check sender domains rather than display names, since the real organization's name appeared only before the @ sign. Microsoft recommends phishing-resistant authentication, Conditional Access policies, endpoint detection in block mode, Safe Links and Safe Attachments, zero-hour auto purge and network protection. The Hacker News reported Microsoft also advises hunting for the group's scheduled tasks and restricting outbound SSH, a remote-access protocol.
Boards and general counsel at think tanks, trade groups and event organizers face a different risk: their brand is the bait. If your organization hosts events, warn members and speakers about impersonation, publish how genuine invitations will arrive, and give recipients a way to check. Because the emails came from real but compromised websites, reputation filters alone may not stop them.
The bigger picture
CyberScoop described Microsoft's findings as a shift from targeted spear-phishing to large-scale campaigns. That suggests state espionage groups are trading precision for volume, which widens the net to consultancies, banks, law firms and companies that sit near policy work. Microsoft said the group's shift from Ukraine to global targets could mean it first used Ukraine to test its new tools.
What’s next
Watch for any disclosure of confirmed compromises, for new lures tied to upcoming conferences, and for advisories from government cyber agencies in the US and UK that add detection guidance for RedFlick and CosmicPulse.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








