Russian state-sponsored group Star Blizzard has been sending fake event invitations to compromise Windows machines, according to a Microsoft report. The campaigns, active since January, have affected more than 100 organizations tied to Ukraine, mostly in the U.S. and U.K. Microsoft attributes the activity to Star Blizzard, which security agencies from the U.S., U.K., Australia, Canada and New Zealand previously linked to Center 18 of Russia's FSB.

Microsoft calls the new delivery method RedFlick. It uses scheduled tasks to install a Python-based backdoor named CosmicPulse. The infection chain starts with an LNK file disguised as a PDF, which fetches a Windows Installer package that creates three scheduled tasks with names resembling legitimate network components. Those tasks communicate with a command-and-control server and run the next stage.

Early campaigns posed as Ukrainian authorities and sent fake tax audits and water shutdown notices. Later lures used invitations from think tanks like Chatham House and the Atlantic Council. One March campaign sent an iPhone exploit kit, DarkSword, to respondents, though Microsoft's confidence is medium because the exploit pages were offline. Microsoft also notes overlaps with a June campaign reported by Digital Security Lab Ukraine, but says shared indicators alone do not prove the same group ran both.

Defenders can look for the three scheduled task names and Microsoft Defender detections for RedFlick and CosmicPulse. Microsoft also recommends verifying sender addresses, since the real organization name appears before the @ sign, and blocking unnecessary outbound SSH connections.