Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Star Blizzard Targets 100+ Organizations With Fake Event Invitations, and Canadian Think Tanks Should Take Note

What Happened

Microsoft reports Star Blizzard, a Russian state group tied to Center 18 of the FSB, has targeted more than 100 organizations since January 2026. The group sends fake event invitations posing as Chatham House and the Atlantic Council. Other lures include tax audit notices aimed at Ukr.net users, water shutdown notices for Kyiv hotels, and payment notices for staff of international financial organizations.

The toolset includes CosmicPulse, a Python backdoor, a scheduled-task delivery method called RedFlick, and a downloader tracked as NOROBOT or BAITSWITCH. A March variant also carried DarkSword, an iPhone exploit kit. Microsoft revised the infection chain in July. Most affected organizations sit in the United States and the United Kingdom, with a focus on government bodies, NGOs, and think tanks tied to Ukraine. See the report at The Hacker News.

Why This Matters for Canadian Organizations

Canada was among the countries whose security agencies warned about Star Blizzard in December 2023. The group has not moved on. Canadian think tanks, university research centres, NGOs, and federal and provincial policy teams host the same kind of events and hold the same kind of contacts as the organizations now being hit.

Invitations to closed-door policy events look routine to these teams. This routine is the attack surface. A single click on a realistic invitation gives a state actor a foothold in an inbox full of diplomatic and policy correspondence. Staff travelling to conferences on iPhones also fall within reach of the DarkSword kit.

What to Do

Verify event invitations through a second channel before opening attachments or links. Block scheduled-task creation from Office child processes and alert on it. Turn on Lockdown Mode for high-risk staff and keep iOS fully patched. Train executives and policy staff on invitation lures specifically, since generic phishing training misses them. Watch for new scheduled tasks and Python processes on workstations tied to outreach and communications roles.

Read more analysis in our Trends section and daily updates in News.

Enjoy this article? Don’t forget to share.