← Volver al blog

Russian Hackers Use Fake Event Invites to Deploy Backdoors

Star Blizzard targets 100+ orgs with phishing emails伪装成活动邀请. Microsoft confirms at least one infection via malicious Windows backdoor.

Resumen

  • Russian state hackers Star Blizzard launched phishing attacks using fake event invites.
  • Over 100 organizations targeted, mainly in the US and UK.
  • Emails were tailored to entities connected to Ukraine.
  • At least one system was compromised with a Windows backdoor.
  • Microsoft disclosed the campaign and linked it to ongoing geopolitical cyber operations.

Cybersecurity researchers at Microsoft have uncovered a new wave of attacks by Russian state-sponsored hacking group Star Blizzard. The group has been distributing malware-laced event invitations to infiltrate networks associated with Ukraine.

Since January, over 100 organizations across the U.S. and U.K. have received these deceptive messages. While exact breach numbers remain unclear, Microsoft confirmed that at least one device was successfully infected with a Windows-based backdoor.

Attack Vector and Targeting Strategy

  • Star Blizzard used spear-phishing emails disguised as legitimate event invitations.
  • Targets included government bodies, NGOs, and private firms with ties to Ukraine.
  • Emails contained embedded links or attachments leading to backdoor installation.
  • Most attacks occurred in Western countries including the U.S. and U.K.

Technical Details and Defense Recommendations

  • The malware deployed is a custom Windows backdoor designed for persistent access.
  • Organizations should enforce email filtering and user training to detect social engineering tactics.
  • Indicators of compromise (IOCs) were shared with threat intelligence communities.
  • Microsoft recommends enabling multi-factor authentication and monitoring for unusual network activity.

Sources

Fuentes

Novedades de seguridad por correo

Un correo resumen cuando publicamos nuevos artículos de seguridad (resumen más enlaces para leer más). Date de baja cuando quieras desde el pie del mensaje. Consulta nuestra Política de privacidad.