Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites

Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Table of Contents
    Add a header to begin generating the table of contents

    Microsoft says the Russian state-sponsored hacking group Star Blizzard has used fake event invitations to trick targets into installing a backdoor on Windows computers, affecting more than 100 organizations tied to Ukraine since January 2026, primarily in the United States and United Kingdom.

    Fake Event Invitations Deliver a Windows Backdoor

    According to Microsoft, Star Blizzard’s campaign relies on invitations to events as its social-engineering lure, luring targets into a chain that ends with a backdoor installed on their Windows computer. The specific technical delivery mechanism, such as attachment format or the platform used to send the fake invitations, has not been detailed publicly beyond Microsoft’s characterization of the lure itself.

    Microsoft has confirmed at least one computer infected through the campaign. The company has not disclosed the total number of systems successfully breached across the more than 100 affected organizations, meaning the scale of confirmed backdoor installations versus targeting attempts that were blocked or failed remains unclear from the public disclosure.

    Event-invitation lures are effective against organizations whose staff regularly receive legitimate invitations from unfamiliar contacts, such as conferences, briefings, or policy roundtables tied to their advocacy or aid work. That routine exposure to unsolicited calendar and event content from outside senders is precisely the pattern Star Blizzard’s lure is designed to blend into, making the campaign harder to distinguish from ordinary professional correspondence than a more generic phishing attempt would be.

    Targets Are Individuals and Organizations Tied to Ukraine

    The campaign’s targeting is focused specifically on people and organizations connected to Ukraine, according to Microsoft’s report. The affected organizations are concentrated in the United States and United Kingdom, two of Ukraine’s most significant Western allies, rather than being spread broadly across unrelated sectors or regions. This targeting pattern points toward an intelligence-gathering objective centered on Ukraine-related policy, aid, or advocacy work being conducted in those two countries.

    Star Blizzard Is Also Tracked as Callisto and COLDRIVER

    Star Blizzard is a Russian state-sponsored group also tracked under the names Callisto and COLDRIVER by other parts of the security research community. Microsoft’s naming convention places it within the “Blizzard” family the company uses to categorize Russian-attributed threat activity clusters. The group has been publicly associated with espionage operations before this campaign, and the current activity extends that pattern into a sustained, months-long operation against Ukraine-linked targets in Western countries.

    The use of three separate names for the same group across different parts of the security research community reflects how threat-actor tracking has developed independently at multiple organizations rather than through a single shared naming authority. Readers encountering references to Callisto or COLDRIVER in other reporting on Ukraine-linked espionage activity should treat those names as referring to the same underlying group Microsoft calls Star Blizzard.

    Microsoft Published Indicators of Compromise for the Campaign

    Microsoft’s disclosure included published indicators of compromise and other campaign details intended to help potential targets and their security teams identify related activity. The company is advising organizations with ties to Ukraine policy or aid work to scrutinize unsolicited event invitations and calendar links closely, given that this specific lure format is the entry point Star Blizzard has used throughout the campaign.

    Sustained Campaign Signals Ongoing Intelligence Operations

    The campaign’s roughly nine-month duration, still active at the time of Microsoft’s disclosure, indicates a sustained rather than opportunistic operation. Targeting more than 100 organizations over that span, concentrated on a specific geopolitical theme tied to the war in Ukraine, is consistent with an intelligence-collection objective rather than a financially motivated attack. Microsoft’s decision to publish indicators of compromise gives defenders at potentially targeted organizations a concrete basis for checking their own environments, though the undisclosed total infection count leaves open how many of the 100-plus targeted organizations beyond the one confirmed case actually had a device compromised rather than simply receiving the lure.

    The one confirmed infection Microsoft has disclosed represents a floor rather than a ceiling on the campaign’s real-world impact, since organizations that received the fake event invitation but did not detect or report a resulting compromise would not be reflected in that figure. Microsoft’s published indicators give affected organizations a way to check retroactively for signs of the backdoor even if they were not aware they had been targeted.

    Related Posts