Star Blizzard Unleashes RedFlick: Russian Hackers Target Ukraine Allies with Fake Event Invites and New Backdoor
Russian state-sponsored hacking group, **Star Blizzard** (also known as **Callisto Group** or **ColdRiver**), is employing sophisticated spear-phishing campaigns using fake event invitations to deploy a new backdoor, **CosmicPulse**, on Windows systems. These attacks, primarily targeting organizations linked to Ukraine in the U.S. and U.K., have affected over 100 entities since January, according to **Microsoft**.
Russian state hackers, identified as **Star Blizzard**, are escalating their campaigns against organizations and individuals connected to Ukraine, leveraging deceptive event invitations to compromise Windows computers. **Microsoft** reports that these campaigns have impacted more than 100 organizations since January, predominantly in the U.S. and U.K., with at least one confirmed infection.
International security agencies, including those from the U.S., U.K., Australia, Canada, and New Zealand, collectively attributed **Star Blizzard** to Center 18 of Russia's **Federal Security Service (FSB)** in December 2023. The group has a history of credential theft via social engineering, often impersonating known contacts of their targets.

### Evolving Tactics: From ClickFix to RedFlick
By 2023, **Star Blizzard** was already using fake conference and event invitations as bait, frequently engaging in initial message exchanges before delivering malicious links. **Microsoft** has tracked at least 13 major campaigns this year, each involving tens to hundreds of emails, in addition to the group's ongoing targeted phishing efforts.
Since March, the group has shifted its infrastructure, utilizing compromised WordPress and cPanel website email accounts, a departure from their previous reliance on free email services like Proton and **Microsoft** consumer accounts.
In 2025, the group employed a technique dubbed **ClickFix**, which involved fake CAPTCHA pages tricking targets into executing commands themselves. This year, they transitioned to a new method **Microsoft** calls **RedFlick**, which leverages scheduled tasks in Windows to install the **CosmicPulse** backdoor.
### The Allure of Deception
The fake invitations often impersonate reputable think tanks or NGOs, such as **Chatham House** and the **Atlantic Council**. Many emails are crafted to appear as if they originate from within the target's own organization.
The initial email typically contains no attachments. If the target replies, the attackers send a password-protected RAR or ZIP archive, with the password conveniently provided within an image in the email itself.
Early campaigns in January and February mimicked Ukrainian authorities, sending fraudulent tax audit and fine notices to users of the Ukrainian email service **Ukr.net**. Subsequent lures included notices of water shutdowns for Kyiv hotels and payment notifications for staff at international financial organizations.
One notable campaign in March deviated from the norm. Individuals who responded to an **Atlantic Council**-themed invitation were directed to **DarkSword**, an iPhone exploit kit, instead of the typical Windows backdoor. This was independently reported by **Proofpoint**, which observed a significant increase in email volume from the group around that time.
**Trellix** also identified four such emails on March 26. While their confidence in the **DarkSword** link is medium due to offline exploit pages, the intent was clear.

### Unpacking the Infection Chain
**Microsoft** has analyzed several versions of the infection chain. In all observed cases, a shortcut (LNK) file, disguised as a PDF document, initiates the attack. A Windows Installer (MSI) package then proceeds to set up scheduled tasks.
Opening the LNK file discreetly executes commands that retrieve the installer from a remote server. In January, a hidden script used the SSH program for this download. By July, the shortcut downloaded a PDF containing a hidden command designed to fetch the installer.

The April version of the installer created three scheduled tasks, cleverly named to mimic legitimate network components:
* **Internet Quality Test Connection**
* **Network Configuration Manager**
* **System Health Monitor**
The first task exfiltrates the computer name and user name to the group's command-and-control (C2) server and can execute additional remote code. The second configures **WebDAV**, a Windows feature that maps a web address as a local folder. The third utilizes `control.exe`, the Windows Control Panel program, to run the next stage from the C2 server.
This subsequent stage is a downloader, also disguised as a Control Panel item, which ultimately installs **CosmicPulse**, a Python-based backdoor. This downloader has previously been identified as **NOROBOT** or **BAITSWITCH**.
**Microsoft** notes overlaps between these techniques and a June campaign reported by **Digital Security Lab Ukraine**, which targeted Ukrainian civil society organizations with fake invitations to the Ukraine Recovery Conference. While the lab did not name the attackers, a comparison by The Hacker News found two shared indicators: the IP address `103.160.59[.]97` and the domain `secure-dns-hub[.]com`.
### Recommendations for Defenders
**Microsoft** has released hunting queries and indicators of compromise for these campaigns, specifically advising government bodies, NGOs, and think tanks involved in or supporting Ukraine policy. The company also proactively notifies targeted or compromised customers.
As of **Microsoft**'s report publication on September 29, the domain `secure-dns-hub[.]com` was still active.
Organizations at risk of being targeted should implement the following defensive measures:
* **Verify Sender Addresses**: In these campaigns, the legitimate organization's name often appears *before* the `@` sign, rather than within the domain. When in doubt, contact the sender using a pre-verified phone number or email address.
* **Scan for Indicators**: Search for the three scheduled task names mentioned above, as well as **Microsoft Defender** detections for `Trojan:Script/RedFlick` and `Backdoor:Python/CosmicPulse`.
* **Extend Log Retention**: While **Defender XDR**'s advanced hunting retains 30 days of raw data, extending log retention to services like **Microsoft Sentinel** is crucial for investigating attacks dating back to January.
* **Restrict Outbound SSH**: Block or limit outbound SSH connections that are not essential for business operations, as the January attack vector leveraged SSH to fetch the installer.
* **Enable Attack Surface Reduction (ASR) Rules**: For **Microsoft Defender** users, activate ASR rules that prevent the execution of rare, new, or untrusted executables and obfuscated scripts.
* **Implement Phishing-Resistant MFA**: Utilize sign-in methods that are resistant to phishing, as **Star Blizzard** continues to employ password phishing with tools like **Evilginx**, which can steal session cookies to bypass two-factor authentication.
* **Update iOS Devices**: **Trellix** advises updating iPhones to **iOS 26.3** or later, which patches all six vulnerabilities exploited by **DarkSword**. Where immediate updates are not feasible, enable **Lockdown Mode**.
While **Microsoft**'s public report does not detail specific cleanup steps for compromised machines, **Defender XDR** customers can refer to the company's threat analytics reports for recommended response actions.