Star Blizzard fake event-invitation phishing campaign
Campaign
Summary
Hide ▲
Show ▼
Star Blizzard has run a fake event-invitation phishing campaign that delivers a Windows backdoor to people and organizations tied to Ukraine, affecting more than 100 organizations since January. The operation uses repeated email waves, spoofed host organizations, and malicious archives or links to push its payloads. Microsoft says at least one computer was infected, and the same operation has used multiple lure variants to keep pressure on the target set. Defenders can look for the named scheduled tasks and indicators tied to the campaign.
Related Happenings
GTG-30006 Claude-assisted malware and phishing pipeline
Malware Activity
H score20
First: 11.09.2026 17:29
Last: 11.09.2026 17:29
Sources 1
About this happening:
An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of ...
GTG-30006 Claude-assisted malware and phishing pipeline
Malware ActivityAbout this happening: An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of ...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
H score37
First: 04.08.2026 03:17
Last: 04.08.2026 03:17
Sources 1
About this happening:
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
CampaignAbout this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Timeline
-
29.09.2026 20:20 1 articles · 2h ago
Atlantic Council-themed emails lead recipients to DarkSword
Technical Analysis UpdatePeople who replied to an Atlantic Council-themed invitation were sent a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor. Trellix found four such emails on March 26 and said confidence was medium because the exploit pages were offline and no exploit code was recovered.
Show sources
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor — thehackernews.com — 29.09.2026 20:20
-
29.09.2026 20:20 2 articles · 2h ago
Star Blizzard phishing campaign affects more than 100 Ukraine-linked organizations
Initial DisclosureMicrosoft says Star Blizzard has been using fake event invitations to deliver a Windows backdoor to people and organizations tied to Ukraine, with more than 100 organizations affected since January and at least one computer infected. Since March, the campaigns have used email accounts on WordPress and cPanel websites, and Microsoft published hunting queries and indicators on September 29.
Show sources
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor — thehackernews.com — 29.09.2026 20:20
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor — thehackernews.com — 29.09.2026 20:20