Russia's Star Blizzard Cyber Espionage Campaign Uses Fake Event Invites to Deploy Backdoor
Russia's Star Blizzard, linked to the FSB, has targeted over 100 organizations with phishing campaigns using fake event invites to deploy the CosmicPulse backdoor via RedFlick techniques. The attack leverages scheduled tasks and spoofed sender addresses to compromise Windows systems, with indicators tied to previous Ukrainian-focused campaigns.
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
*** END OF TRANSMISSION ***