Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Sep 29, 2026
Malware / Cyber Espionage
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been disclosed. Security agencies in the U.S., U.K., Australia, Canada and New Zealand said in December 2023 that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB). The group has long stolen email passwords by posing as people its targets know. By 2023, it had already used fake conference and event invitations as bait, often exchanging messages with a target before sending a malicious link. Microsoft counted at least 13 larger campaigns this year, each with tens to hundreds of emails, on top of ...