Nine of 13 Star Blizzard campaigns are event invitations, and the invitation usually has no attachment
Microsoft lists 13 Star Blizzard campaigns since January and says over 100 organisations were affected. Nine are event lures, the invitation usually carries no attachment, and the report gives no count of compromised organisations.
By Parminder Kumar Sharma · · 19 min read

Nine of 13, and the invitation itself usually carries nothing
Microsoft's report of 29 September 2026 lists 13 Star Blizzard phishing campaigns between January and August. Nine are event lures: a roundtable, a forum, a summit, a conference or a closed-door session. Four are not: a tax audit notice, a fine, a water shutdown notice and a payment advice. Nine of 13 is 69 per cent (derived: our count of Microsoft's subject lines, set out in full below). The headlines say fake event invitations install a Windows backdoor. On Microsoft's account the invitation is usually a plain email with no attachment. The archive that leads to the backdoor arrives in a second message, which Microsoft says is typically sent only once the recipient responds.
What that does not establish. It does not establish how many organisations were compromised. Microsoft says it has seen the activity "affect over 100 organizations", primarily in the United States and United Kingdom, and it gives no compromised count. The only infection it describes is one incident in which a scheduled task deployed the backdoor on a machine. It does not define "affect", split the US from the UK, or tie the 100 to the 13 campaigns. It gives no confidence level for linking the 2026 campaigns to Star Blizzard: the one "high confidence" in the post concerns the hijacked websites that send the mail. The link between Star Blizzard and Russia's Federal Security Service (FSB) rests on a government assessment of 7 December 2023, 1,027 days before this post (derived). And the post does not say what Microsoft cannot see.
What Microsoft's post fixes, and what it leaves open
Microsoft is the only primary source for the 2026 campaigns as a whole. One independent report, from Digital Security Lab Ukraine (DLUA), covers a single June campaign, and The Hacker News's account of 29 September rests on Microsoft's post. The table separates what the post states from what it does not. "Not stated" means the post is silent, not that the answer is no.
Microsoft Threat Intelligence, 29 September 2026, read in full on 30 September. Right-hand column: our reading of what the post does not say.
| Question | On the record | Not stated |
|---|---|---|
| How many organisations? | Over 100 "affected", primarily in the United States and United Kingdom. | What "affected" means. How many were compromised. The US and UK split. Whether the count is Microsoft customers only. |
| How many campaigns? | At least 13 large-scale campaigns since January 2026, each of tens to hundreds of messages. The timeline lists 13. | A total message count. The separate targeted spear-phishing. Whether DLUA's June invitation campaign is one of the 13. |
| How many infected? | In at least one incident, the first or third scheduled task deployed CosmicPulse on the infected machine. | Any count of infected machines or organisations. What was taken. How long it stayed. |
| Who is behind it? | Star Blizzard, which Microsoft says CISA attributes to FSB Centre 18. | A confidence level, or the evidence linking the 2026 campaigns to the actor. "High confidence" is given only for the hijacked mail-sending websites. |
| What does the backdoor do? | A Python backdoor whose capabilities and purpose "remain the same" as in earlier articles. | A description in this post. What one remote payload run by the first April task was: Microsoft could not obtain it. |
| What can Microsoft see? | It notifies customers it sees as targeted or compromised. | The telemetry behind the counts. Anything outside its customers' view. |
The 13 campaigns, counted
Microsoft's timeline gives a subject line, a target group and what respondents received for each campaign, which is enough to check the headline. We counted a campaign as an event lure when its subject line invites the recipient to, or points them at, a roundtable, forum, summit, conference or closed-door session. Subject lines are paraphrased except where quoted.
The 13 campaigns in Microsoft's timeline (29 September 2026), with our classification in the third column.
| Month | Lure and who it targeted | Kind, and what the target received |
|---|---|---|
| January | Notice of tax audit results, to unidentified users of Ukr.net in Ukraine. | Not an event. RedFlick lure attached. |
| February | A fine debited from your account, to unidentified users in Ukraine. | Not an event. RedFlick lure attached. |
| March | Invitation to an IISS private roundtable on European security: officials, researchers, academia, media, NGOs. | Event. RedFlick attachment to respondents. |
| March | Invitation to a closed CES roundtable: US and European technology firms. | Event. RedFlick attachment to respondents. |
| March | Atlantic Council closed-door strategic discussion: officials, researchers, academia, media, NGOs. | Event. Respondents got a link to install the DarkSword iOS backdoor. |
| April | Closed-door online session on global capital allocation and M&A: financial organisations, researchers. | Event. RedFlick attachment to respondents. |
| May | Future of Peace Operations Forum, a closed strategic dialogue: diplomatic and multilateral organisations. | Event. RedFlick attachment to respondents. |
| May | Future of Liberty Forum: staff of a US-based think tank. | Event. RedFlick attachment to respondents. |
| June | Invitation to the MAMA Summit on the Ukrainian crisis: current and former diplomatic staff. | Event. RedFlick attachment to respondents. |
| June | Invitation to the Chatham House London Conference 2026: think tanks, NGOs and others. | Event. RedFlick attachment to respondents. |
| July | "Thought you might find this USUBC roundtable of interest": think tanks, NGOs, Ukraine civil society. | Event (a shared roundtable notice). RedFlick attachment to respondents. |
| July | Information about a temporary water supply shutdown: Kyiv-based hotels. | Not an event. RedFlick lure attached. |
| August | Payment advice note dated 6 August 2026: staff of an international financial organisation. | Not an event. RedFlick lure attached. |
The arithmetic: 9 event lures plus 4 others make 13. Twelve campaigns delivered a RedFlick lure attachment and one, the March Atlantic Council theme, sent respondents a link to install DarkSword. Eight of the nine event campaigns delivered the RedFlick attachment. The ninth event lure, the July USUBC one, is a forwarded roundtable notice rather than a formal invitation, so counting it is our call; without it the figure is 8 of 13, or 62 per cent (derived). On the March DarkSword theme, The Hacker News reported Proofpoint as saying it was not known whether any of those attacks succeeded and that all messages targeting its customers were blocked. That is second-hand: we did not read Proofpoint's own post.
Two cautions. First, "at least 13" is a floor. DLUA's report describes a campaign from 10 June that used fake Ukraine Recovery Conference invitations. That theme is not among Microsoft's June subject lines, and Microsoft says only that its persistence techniques overlap with the DLUA report. DLUA names no actor. We checked both indicator lists: one IP address and one domain appear in both. Shared infrastructure points to a link; it does not by itself show the same operators. Second, four of the 13 are not events, so "event invitation" describes the commonest lure, not the technique. The technique is the two-message chain in the next section, and it also carried a payment notice.
Where the invitation stops and the code starts
The diagram sets the chain Microsoft describes for January and July against what the person sees at each step. Read across it and the invitation is the least dangerous step and the only one the recipient reads as an event.
Microsoft's description has the first email arriving with nothing to run. DLUA, describing its June sample, adds that the first email referred to a registration form "in the attached file" although nothing was attached, and that a message with no payload passes mail scanning cleanly. That is DLUA's reading of its own sample, not Microsoft's. The archive follows in a second message, and its password is a picture.
Microsoft describes two delivery chains in detail. In mid-January a password-protected ZIP held a virtual hard disk (VHDX) with a shortcut file disguised as a PDF, a hidden script and a genuine decoy PDF. Opening the shortcut ran the script, which opened the decoy and used the SSH client to download and run a Windows Installer (MSI) package. In July a password-protected RAR nested inside a ZIP exposed a shortcut that used curl to fetch a PDF; a hidden encoded command in that PDF was extracted and run to fetch another MSI. In both, the installer creates scheduled tasks and a downloader built as a Control Panel applet installs the CosmicPulse Python backdoor. In April the installer created three tasks named like network components.
At the level a defender needs, that is a short list. The human steps are ordinary: reply, open a message, extract an archive, open a file that looks like a PDF. The machine steps use programs that ship with Windows: a script host, the SSH client, curl, the installer service, the task scheduler and the Control Panel launcher. DLUA adds one mechanism Microsoft's post does not discuss: files opened from a mounted disk image do not carry the "downloaded from the internet" mark, so the usual SmartScreen warning never appears. Treat that as DLUA's analysis of its June sample.
Six labels that reassure, and none of them is a control
A comforting label is not a control. Each label in this chain reassures someone, and the sources say what stands behind it.
Labels in the RedFlick chain, who they reassure, and what Microsoft and DLUA say they are.
| Label | Who it reassures | What the sources say |
|---|---|---|
| Invitation | The recipient. A filter that looks for attachments or links. | Usually an email with no attachment (Microsoft). The code comes in a second message. |
| Closed-door, confidential, password-protected | The recipient: exclusivity reads as legitimacy (our reading). | A password-protected RAR or ZIP, the password shown as an image (Microsoft). Why it is an image is not stated. |
| Anyone checking an icon or a file name. | A shortcut (LNK) file disguised as a PDF (Microsoft). In July, a real PDF that hid an encoded command. | |
| Single user interaction | A risk register, an awareness course. | Microsoft's phrase for the infection step, compared with ClickFix. It does not count what came before it. |
| Network Configuration Manager, System Health Monitor, Internet Quality Test Connection | An administrator glancing at the task list. A hunt that matches names. | Three scheduled tasks created by the installer in April, named to look like network components. July's tasks are unnamed in the post. DLUA's June sample used other names. |
| Control Panel applet | Application control that trusts control.exe. | A downloader compiled as a Control Panel applet DLL, loaded by a genuine Windows process from a remote path (Microsoft). |
One label needs a further word. Microsoft says the RedFlick flow "only requires a single user interaction", against the earlier ClickFix chains that needed several actions (this site covers ClickFix in the custom GPT briefing). That compares the infection step with the older infection step. It does not count what the person did before it. By our count of what Microsoft describes, a person replies to an unsolicited invitation, opens a second message, reads a password from a picture, extracts a protected archive and, in January, opens a virtual disk before the final open. "Single" is true of the last click and misleading as a description of risk.
"Event invitation" also hides a negative worth stating. Microsoft's post describes emails. It does not mention a calendar item, a meeting request or any invitation file format. The invitation is a costume made of email text, and nothing in the sources says a calendar feature was involved.
What the UK sources say, and what they do not
This section states only what the sources say about the United Kingdom and this actor. It draws no conclusion beyond them.
UK-relevant statements about Star Blizzard, from Microsoft (2026) and UK government sources (2023). No UK government statement on the 2026 activity was found by 12:15 BST on 30 September 2026.
| Source and date | What it says | Not stated |
|---|---|---|
| Microsoft, 29 September 2026 | Over 100 organisations affected, "primarily in the United States and United Kingdom". A June lure used the Chatham House London Conference 2026 as its theme. | How many are British. Whether any was compromised. Whether the named event organisers were involved: Microsoft calls the lures purported. |
| NCSC and CISA advisory, 7 December 2023 | Assessed "almost certainly subordinate" to FSB Centre 18. Continues to use spear-phishing against targets "in the UK". UK and US targets "appear to have been most affected". Has used conference or event invitations as lures, and mostly writes to personal email addresses. | Any malware. That advisory describes credential theft by links and mail forwarding rules. Nothing on 2026. |
| NCSC news release, 7 December 2023 | Targeting of UK parliamentarians from at least 2015, the 2018 compromise of the Institute for Statecraft, and targeting of universities, journalists, the public sector and NGOs. | Anything after 2023. |
| UK sanctions notice, 7 December 2023 | Two individuals designated under the UK cyber sanctions regulations. The statement of reasons calls the Callisto Group, Star Blizzard, "a cyber programme operated by officers of the Russian FSB". | Any link between those individuals and the 2026 campaigns. |
Read together, the UK government's record establishes that the actor targets UK organisations and had used conference and event invitations by 2023: 1,027 days before Microsoft's post (derived). Microsoft's 2026 report says UK organisations are among the 100 and does not say how many. On the two sources' descriptions, what changed is what follows the reply: in 2023 a link to a credential-stealing page, in 2026 an archive that installs a backdoor, sent at scale from hijacked websites. The NCSC's page still tells UK organisations where to report related activity: report.ncsc.gov.uk.
One actor with eight names, and malware with several
A hunt built from one vendor's name misses another's reports. The NCSC and CISA advisory lists seven names for the actor and Google's Threat Intelligence Group adds an eighth. The malware has the same problem.
Names in the sources for the actor and the tooling, and who uses them.
| Name | Used by | What it refers to |
|---|---|---|
| Star Blizzard | Microsoft; NCSC and CISA | The actor, formerly SEABORGIUM. |
| Callisto Group, TA446, COLDRIVER, TAG-53, BlueCharlie | Listed as aliases in the NCSC and CISA advisory (2023) | The same actor. |
| UNC4057 | Google Threat Intelligence Group (October 2025) | Google's designation, listed with COLDRIVER, Star Blizzard and Callisto. |
| CosmicPulse | Microsoft | The Python backdoor. Microsoft says it is also known as YESROBOT. |
| NOROBOT, BAITSWITCH | Google (NOROBOT); Zscaler (BAITSWITCH); Microsoft lists both | The downloader built as a Control Panel applet. |
| RedFlick | Microsoft | Its name for the scheduled-task delivery technique, and a Defender detection name. |
| MAYBEROBOT | Google (October 2025) | A PowerShell backdoor Google said replaced YESROBOT in 2025. Microsoft's post does not mention it. |
The last two rows matter. Google's October 2025 report said the group dropped the Python backdoor YESROBOT for a PowerShell one. Microsoft's 2026 report describes a Python backdoor under the same alias, with capabilities that "remain the same", and does not say whether the PowerShell backdoor also appears in the 2026 chains. Neither report settles which backdoor a given 2026 intrusion ends with. Search across every name in the table, and track the toolkit, not the name, as the site's Storm-2570 briefing argued.
Who is telling us this, and what they sell
Microsoft sells the products the post's mitigations name: Defender for Office 365, Defender for Endpoint, Defender Antivirus, Entra Conditional Access, Sentinel and Security Copilot. The detection coverage table lists Microsoft detections only, and the hunting queries are written for Defender XDR and Sentinel. That describes where the tooling points; it is not an accusation. The post also publishes 27 indicators (5 file hashes, 16 domains and 6 IP addresses, counted by us), the campaign subject lines and vendor-neutral advice such as restricting outbound SSH. A reader on another stack has to translate, and we have not run any of the queries. One address in the text describing a figure of the post is not in the indicator table, so check the figure against the table before loading anything.
The counts are Microsoft's alone. The post does not say what telemetry they rest on, and it says Microsoft notifies affected customers directly. Our inference, labelled as such, is that the count reflects organisations Microsoft could see rather than every organisation targeted. DLUA is a Ukrainian organisation that investigates phishing against civil society; it names no actor and says it could not retrieve the final payload.
Two comparisons between the coverage and the post. The Hacker News headline pairs "100+ Organizations" with "Fake Event Invites"; the post has nine of 13 listed campaigns as event lures and counts organisations "affected". The Hacker News's text is careful, saying the number of breached organisations has not been disclosed, but a headline number travels alone. Second, The Hacker News says the published Defender XDR queries look back only 7 days. We checked: all three use a 7 day window.
What to harden and hunt, in the order worth doing
Defender guidance only: what to hunt and harden, with no commands, no payload detail and no indicators. Microsoft's indicator table is the place for those.
Take this with you
Order of work
- Check who receives Microsoft's notices. Microsoft says it notifies customers it sees as targeted or compromised. Confirm that message reaches a named person and not a shared inbox nobody reads.
- Search mail you already hold. Look back to 1 January 2026 for the 13 subject lines in Microsoft's timeline, the archive file names in its indicator table, and first-contact external mail that invites staff to a closed-door roundtable or forum. The invitation is the one message with nothing to scan, so its subject line is the only handle.
- Look back further than the published queries do. Microsoft's three Defender XDR queries use a 7 day window, and native advanced hunting keeps up to 30 days of raw data, per Microsoft Learn. The August payment notice is dated 6 August, 55 days before today, and the first campaign is in January. Run the hunts against Sentinel or another store with retention back to 1 January, or say plainly that you cannot.
- Hunt the chain by behaviour, using the patterns Microsoft published: a hidden console host launching curl, the SSH client started with an option that runs a local command, an installer package creating scheduled tasks, and control.exe reaching a remote path. The three task names Microsoft lists cover the April variant only. July's tasks are unnamed in the post, and DLUA's June sample used other names.
- Treat a reply as an event. The archive is sent typically only to people who respond, so ask staff to report unsolicited closed-door invitations without answering, with a one-click way to do it. Microsoft's own tell is that the real organisation's name sits before the at sign in the address, not in the domain. Its post also notes one account name reused across several unrelated hijacked website domains, so a sender name that repeats across unrelated domains is worth an alert. That last alert is our suggestion from Microsoft's observation.
- Hold external archives you cannot inspect. Quarantine or block inbound password-protected RAR and ZIP files, disk images such as VHDX, ISO and IMG, and shortcut files, unless a business owner has asked for them. This is our recommendation, not Microsoft's: the post does not name these file types as policy. A password held in a picture defeats any check that needs the text.
- Add application control to the delivery chain. Use AppLocker or App Control for Windows so that a shortcut opened from an archive, a mounted image or a downloads folder cannot start a script host, cmd, PowerShell, curl, the SSH client or the installer service unattended. Turn on the two attack surface reduction rules Microsoft names, for executables that fail a prevalence or age test and for potentially obfuscated scripts, and block outbound SSH the business does not need, which Microsoft recommends because the January chain used it.
- Look at WebDAV. Microsoft describes the April tasks relying on WebDAV, which retrieves a remote resource over HTTP as if it were a local path. If your endpoints do not use the Windows web-folder client, consider disabling it and alerting on requests that use it. This is our suggestion from that description, untested, and it needs endpoint telemetry or TLS inspection to be useful.
- Cover the personal inbox. The NCSC's 2023 advisory says the group has mostly written to targets' personal email addresses, outside corporate controls. Tell staff in policy, Ukraine-related and think tank roles to forward suspicious invitations from personal accounts to your security team, and say who receives them.
- Keep the identity route closed. Microsoft says the group still runs credential phishing with Evilginx in 2026. Use phishing-resistant sign-in and conditional access, and check mailboxes for external forwarding rules, which the NCSC says the group has used to keep sight of a mailbox after a password reset.
- Do not start with calendars. Nothing in the sources says a calendar item was used; the invitations are email text. If your mail system adds external invitations to calendars automatically, review that separately.
- If you find it, treat it as an espionage intrusion, not commodity malware. Isolate and preserve the machine, list what the account and machine could reach, rotate the credentials that were reachable, and report to the NCSC. Microsoft's public post lists no cleanup steps; it points Defender customers to threat analytics reports for recommended actions.
Everything above is written from Microsoft's and DLUA's descriptions. We have not observed the malware and have tested no control. For the identity item, the site's EvilTokens briefing covers a different phishing kit that also gets past MFA.
The question that exposes the gap
On the sources' accounts the first message is clean, the second is an encrypted archive whose password is a picture, the third step is a shortcut that looks like a PDF, and the first programs it starts all ship with Windows. Each label was a costume, and none of them was a control.
So the question for your estate is not whether your staff can spot a fake invitation. It is this: if the invitation carries nothing, the archive arrives only after a person replies, and the first programs that run are built into Windows, at which step does anything in your estate have a reason to stop it?
Key facts
Sources
- PrimaryPrimary report, 29 September 2026: the 13 campaign timeline, the over 100 organisations figure, the RedFlick chains, defender guidance, hunting queries and indicator table. Read in full.Microsoft Threat Intelligenceaccessed 2026-09-30
- PrimaryReport of 23 June 2026 on fake Ukraine Recovery Conference invitations: first email without an attachment, password in an image, VHDX and shortcut chain, four scheduled tasks, indicators. Read in full.Digital Security Lab Ukraineaccessed 2026-09-30
- PrimaryAdvisory of 7 December 2023 with US, Australian, Canadian and New Zealand partners: FSB Centre 18 assessment, UK targeting, event invitation lures, personal email addresses, mail forwarding rules. Read in full.UK National Cyber Security Centreaccessed 2026-09-30
- PrimaryJoint advisory AA23-341A, 7 December 2023: the same advisory on CISA's site, checked for the attribution wording and the alias list.CISAaccessed 2026-09-30
- PrimaryNews release of 7 December 2023, UK and allies expose Russian intelligence services: targeting of UK parliamentarians, the Institute for Statecraft and civil society. Read in full.UK National Cyber Security Centreaccessed 2026-09-30
- PrimaryFinancial Sanctions Notice, Cyber, 7 December 2023: two designations and the UK statement of reasons describing the Callisto Group. Read in full.HM Treasury, Office of Financial Sanctions Implementationaccessed 2026-09-30
- PrimaryReport of 20 October 2025 on COLDRIVER's NOROBOT, YESROBOT and MAYBEROBOT: used for the alias list and for the backdoor naming history.Google Threat Intelligence Groupaccessed 2026-09-30
- PrimaryAdvanced hunting overview: up to 30 days of raw Defender XDR data, and longer retention through Microsoft Sentinel. Used for the hunt window arithmetic.Microsoft Learnaccessed 2026-09-30
- Reported byNews coverage of 29 September 2026, used as a pointer to the Microsoft report and to compare against it: headline, the 7 day query window and the two shared indicators.The Hacker Newsaccessed 2026-09-30
- Reported byMarch 2026 coverage of Proofpoint's disclosure on Atlantic Council themed emails and DarkSword. Secondary: Proofpoint's own post was not read.The Hacker Newsaccessed 2026-09-30


