Russian state hackers, dubbed Star Blizzard, have employed fake event invitations to trick individuals into installing a backdoor on their Windows computers, as reported by Microsoft. The campaigns targeting organizations linked to Ukraine have impacted over 100 entities since January, primarily in the United States and the United Kingdom. In December 2023, security agencies in the U.S., U.K., Australia, Canada, and New Zealand confirmed that Star Blizzard is almost certainly executed through Center 18 of Russia's Federal Security Service (FSB).
By 2023, they had already used fake conference and event invitations as bait, frequently exchanging messages with their targets before sending malicious links.
The initial campaigns, which occurred in January and February, impersonated Ukrainian authorities and sent fake tax audits and fines to users of the Ukr.net email service. In the version observed in April, the installer created three scheduled tasks that mimic typical network components: Internet Quality Test Connection, Network Configuration Manager, and System Health Monitor. As of September 29, one domain, secure-dns-hub.com, was still active.
If you use Microsoft Defender, enable attack surface reduction rules that block rare, new, or untrusted executable files and obfuscated scripts. Users are advised to update their iPhones to iOS 26.3 or later, as this version addresses all six flaws exploited by DarkSword, and enable Lockdown Mode if it is not yet available.











