Microsoft has disclosed an ongoing campaign by Star Blizzard — the Russian state-sponsored threat actor also tracked as SEABORGIUM, COLDRIVER, and UNC4057, and attributed to Russia's FSB Center 18 — in which the group is distributing fake event invitations to deliver malware to Windows systems. Since January 2026, more than 100 organizations have been targeted, with victims concentrated in the United States and the United Kingdom and overwhelmingly tied to Ukraine-related work: NGOs, think tanks, government entities, defense contractors, academic institutions, and journalists.
At least one endpoint has been confirmed infected, and the true number of compromises is still being assessed. This is not a spray-and-pray phishing wave. Star Blizzard conducts reconnaissance on individual targets, builds rapport over email, and then delivers a personalized invitation — a conference, panel discussion, or policy event relevant to the victim's professional life — that carries a malicious payload. The social engineering is the exploit. Your technical controls are the last line of defense, and this post is about making sure they hold.
If your organization touches Ukraine policy, humanitarian aid, defense research, or Eastern European affairs, treat this as an active, elevated threat condition today.
Technical Analysis
Threat Actor Profile
Star Blizzard has a well-documented operational tempo. The group traditionally focused on credential harvesting via lookalike login pages, but has progressively shifted toward direct malware delivery — a meaningful escalation because it moves the objective from account compromise to persistent endpoint access. The US DOJ seized dozens of Star Blizzard infrastructure domains in 2024, yet the group reconstituted quickly, and this 2026 campaign demonstrates it remains operationally intact.
Attack Chain (Defender's View)
Based on Microsoft's reporting and Star Blizzard's established TTPs, the kill chain breaks down as follows:
- Reconnaissance and persona development (T1589, T1593): Operators research targets through open sources — conference speaker lists, published research, LinkedIn, organizational directories. They often impersonate real colleagues or known figures in the target's field.
- Rapport building (T1566.004 — Spearphishing Link / T1566.001 — Spearphishing Attachment): Initial emails contain no payload. The malicious message arrives later, framed as an event invitation with a link or attachment.
- Delivery: The lure is typically a link to a file hosted on attacker infrastructure or a legitimate-but-abused cloud service, presenting as a PDF invitation, registration form, or agenda document. Payload delivery in Star Blizzard-adjacent campaigns has abused HTML files, LNK shortcuts, and archive files containing script-based loaders.
- Execution on Windows: The payload executes via user-initiated action — double-clicking an attachment that invokes
mshta.exe,wscript.exe,rundll32.exe, or PowerShell — establishing the initial foothold (described in reporting as an unauthorized access mechanism, i.e., a backdoor/RAT implant). - Persistence and C2 (T1547, T1071): The implant establishes persistence — commonly via Registry Run keys or scheduled tasks — and beacons to attacker-controlled infrastructure over HTTPS.
Exploitation Status
- Active, in-the-wild exploitation: CONFIRMED. Microsoft attributes this campaign to Star Blizzard with high confidence and reports 100+ targeted organizations since January 2026.
- Confirmed infection: At least one endpoint compromise acknowledged; full breach scope under assessment.
- CVE: None associated — this campaign relies on social engineering and native Windows tooling (living-off-the-land), not a software vulnerability. That is precisely why patching alone will not save you here.
- CISA KEV: Not applicable (no CVE); however, CISA and allied agencies have previously issued joint advisories on Star Blizzard activity that remain relevant for IOC enrichment.
Why This Campaign Is Dangerous
The group's pre-engagement rapport building defeats the most common user-awareness control — "don't click links from strangers." By the time the invite arrives, the sender is a known, trusted contact to the victim. Detection must therefore be behavior-based at the endpoint, not reputation-based at the perimeter.
Detection & Response
Sigma Rules
The following rules target the observable execution behaviors consistent with document-lure malware delivery on Windows: script interpreters and LOLBins spawning from user-writable directories, and shortcut/script files launching from download locations. Tune the false-positive sections against your own developer and admin baselines before deploying at high severity.
---
title: Script Interpreter or LOLBin Launched From User Download or Temp Directory
id: 3f8a2c41-7b19-4e5d-9c02-8a1f6d4e5b7c
status: experimental
description: Detects mshta, wscript, cscript, or rundll32 executing content from user Downloads, Temp, or AppData paths — consistent with Star Blizzard-style fake invitation lure execution on Windows endpoints.
references:
- https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
- https://attack.mitre.org/techniques/T1566/001/
- https://attack.mitre.org/techniques/T1218/005/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1218.005
- attack.t1059.005
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\mshta.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\rundll32.exe'
selection_path:
CommandLine|contains:
- '\Downloads\'
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- 'C:\Users\Public\'
condition: selection_img and selection_path
falsepositives:
- Legitimate software installers running from Downloads (SCCM/Intune deployments typically run from other paths)
- Developer tooling and self-extracting utilities
level: high
---
title: Office or PDF Reader Spawning Script Interpreter or Command Shell
id: 6c1d9e52-4a78-4f3b-b812-2e7a5c9d1f34
status: experimental
description: Detects document-viewing applications (Acrobat, Office, browsers used as viewers) spawning cmd, powershell, wscript, cscript, or mshta — a strong indicator of malicious document lure execution such as fake event invitation attachments.
references:
- https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
- https://attack.mitre.org/techniques/T1204/002/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.execution
- attack.t1204.002
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\AcroRd32.exe'
- '\Acrobat.exe'
- '\WINWORD.EXE'
- '\EXCEL.EXE'
- '\POWERPNT.EXE'
- '\OUTLOOK.EXE'
- '\msedge.exe'
- '\chrome.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
condition: selection_parent and selection_child
falsepositives:
- Browser-launched installers triggered by users downloading legitimate software — whitelist known installer parent-child pairs
- Enterprise PDF plugins with scripting integrations
level: high
---
title: Persistence via Registry Run Key From Suspicious Path
id: 9b4e7f16-2c53-4d8a-a617-5f9b3e8c2d41
status: experimental
description: Detects registry Run/RunOnce key modifications pointing to executables in user-writable or temp locations, consistent with backdoor persistence following initial lure execution.
references:
- https://attack.mitre.org/techniques/T1547/001/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
selection_key:
TargetObject|contains:
- '\Software\Microsoft\Windows\CurrentVersion\Run'
selection_value:
Details|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- 'C:\Users\Public\'
- '\Downloads\'
condition: selection_key and selection_value
falsepositives:
- Legitimate per-user applications installing auto-start entries (Zoom, Teams, Spotify) — whitelist known-good publishers and paths
level: high
KQL — Microsoft Sentinel / Defender XDR Hunt
This query hunts for the lure-execution pattern across your estate: document viewers and browsers spawning script interpreters, and script interpreters executing from user-writable paths. Run it over a 30-day lookback during initial triage, then operationalize as an analytic rule with entity mapping to Account and Device.
// Hunt: Fake-invitation lure execution chain — Star Blizzard-style delivery
// Lookback: 30 days. Map Account and Device entities when converting to an analytic rule.
let lookback = 30d;
let ScriptHosts = dynamic(["mshta.exe","wscript.exe","cscript.exe","rundll32.exe","powershell.exe","pwsh.exe","cmd.exe"]);
let Viewers = dynamic(["acrord32.exe","acrobat.exe","winword.exe","excel.exe","powerpnt.exe","outlook.exe","msedge.exe","chrome.exe","firefox.exe"]);
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ (ScriptHosts)
| where InitiatingProcessFileName in~ (Viewers)
or ProcessCommandLine has_any (@"\Downloads\", @"\AppData\Local\Temp\", @"\AppData\Roaming\", @"C:\Users\Public\")
| extend SuspiciousChild = FileName, ParentProc = InitiatingProcessFileName
| join kind=leftouter (
DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where RemoteUrl !endswith ".microsoft.com" and RemoteUrl !endswith ".windows.com"
| project DeviceId, InitiatingProcessFileName2 = InitiatingProcessFileName, RemoteUrl, RemoteIP, NetTimestamp = Timestamp
) on DeviceId, $left.FileName == $right.InitiatingProcessFileName2
| summarize
FirstSeen = min(Timestamp),
LastSeen = max(Timestamp),
CommandLines = make_set(ProcessCommandLine, 5),
RemoteDestinations = make_set(strcat(RemoteUrl, " (", RemoteIP, ")"), 10)
by DeviceName, AccountName, ParentProc, SuspiciousChild
| order by FirstSeen asc
Velociraptor VQL — Endpoint Forensic Sweep
Use this artifact to sweep endpoints for recently created shortcut and script files in user download/desktop locations (potential lure remnants) alongside persistence entries pointing at user-writable paths. Deploy as a hunt across the at-risk OU or user population first.
-- Star Blizzard lure artifact sweep: suspicious files in user-facing dirs + persistence pointing to user-writable paths
LET lure_files = SELECT
FullPath,
Size,
Mtime AS Modified,
Btime AS Created
FROM glob(
globs=[
'C:/Users/*/Downloads/*.lnk',
'C:/Users/*/Downloads/*.hta',
'C:/Users/*/Downloads/*.js',
'C:/Users/*/Downloads/*.vbs',
'C:/Users/*/Desktop/*.lnk',
'C:/Users/*/AppData/Local/Temp/*.hta',
'C:/Users/*/AppData/Local/Temp/*.lnk'
],
accessor='ntfs'
)
WHERE Mtime > now() - 2592000 -- last 30 days
LET persistence = SELECT
FullPath AS KeyPath,
{ SELECT Name, Data.value AS Value FROM stat(filename=FullPath) } AS Entry
FROM glob(globs='HKEY_USERS/*/Software/Microsoft/Windows/CurrentVersion/Run*/*', accessor='registry')
WHERE FullPath =~ '(?i)(appdata|temp|public|downloads)'
SELECT * FROM lure_files
UNION ALL
SELECT * FROM persistence
If Velociraptor's registry glob returns limited data in your version, split the two queries into separate artifacts — Windows.Forensics.Lnk for shortcut parsing and Windows.Registry.RunKeys filtered on user-writable paths are solid built-in alternatives.
Hardening & Verification Script
This PowerShell script (run elevated) enables high-value Microsoft Defender Attack Surface Reduction rules relevant to this campaign, verifies SmartScreen and Mark-of-the-Web handling, and audits for persistence entries in suspicious locations. Review ASR rules in audit mode first if you have legacy line-of-business apps.
# Star Blizzard fake-invite campaign — endpoint hardening and posture verification
# Run elevated. Test ASR rules in AuditMode (value 2) before enforcing (value 1) in sensitive environments.
# 1) Enable ASR rules that break the lure-execution chain
$asrRules = @{
"D4F940AB-401B-4EFC-AADC-AD5F3C50688A" = 1 # Block Office apps from creating child processes
"56A863A9-875E-4185-98A7-B882C64B5CE5" = 1 # Block abuse of exploited vulnerable signed drivers
"5BEB7EFE-FD9A-4556-801D-275E5FFC04CC" = 1 # Block execution of potentially obfuscated scripts
"D3E037E1-3EB8-44C8-A917-57927947596D" = 1 # Block JS/VBS from launching downloaded executable content
"3B576869-A4EC-4529-8536-B80A7769E899" = 1 # Block Office apps from creating executable content
"92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B" = 1 # Block Win32 API calls from Office macros
}
foreach ($rule in $asrRules.GetEnumerator()) {
Add-MpPreference -AttackSurfaceReductionRules_Ids $rule.Key -AttackSurfaceReductionRules_Actions $rule.Value
}
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Ids
# 2) Enforce SmartScreen for Edge and Windows (blocks known-bad lure sites/files)
Set-MpPreference -EnableSmartScreen $true
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Force | Out-Null
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\System" -Name "EnableSmartScreen" -Value 1
# 3) Enforce Mark-of-the-Web: force zone checks on downloaded files (strips silent-execution paths)
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\AttachmentManager" -Force | Out-Null
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\AttachmentManager" -Name "SaveZoneInformation" -Value 1
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\AttachmentManager" -Name "ScanWithAntiVirus" -Value 3
# 4) Audit: persistence entries pointing at user-writable paths (potential implant footholds)
$runKeys = @(
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce",
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce"
)
foreach ($key in $runKeys) {
if (Test-Path $key) {
Get-ItemProperty -Path $key | ForEach-Object {
$_.PSObject.Properties | Where-Object {
$_.Value -match "AppData|Temp|Public|Downloads"
} | ForEach-Object {
Write-Warning "Suspicious persistence: $($key) :: $($_.Name) = $($_.Value)"
}
}
}
}
# 5) Audit: scheduled tasks executing from user-writable paths
Get-ScheduledTask | ForEach-Object {
$task = $_
$task.Actions | Where-Object {
$_.Execute -match "AppData|Temp|Public|Downloads" -and
$_.Execute -notmatch "OneDrive|Teams|Spotify|Zoom"
} | ForEach-Object {
Write-Warning "Suspicious task: $($task.TaskName) -> $($_.Execute) $($_.Arguments)"
}
}
Remediation
Because there is no CVE and no patch, remediation is about posture, hunting, and containment. Prioritize in this order:
Immediate (24–72 hours):
- Scope exposure. Identify all staff whose work touches Ukraine, Russia policy, humanitarian aid, defense research, or adjacent NGO/diplomatic communities. These are Star Blizzard's target set. Brief them directly and personally — not via a mass email they'll skim.
- Deploy the detection content above. Enable the Sigma-derived analytics and the KQL analytic rule in Sentinel/Defender. Run the 30-day retrospective hunt before assuming you're clean.
- Enforce ASR rules. The rules in the script above (especially blocking Office child processes and JS/VBS launching downloaded content) directly break this campaign's execution chain. Audit mode first if needed; enforce within the week.
- Verify email authentication controls. Enforce DMARC at
p=rejecton your domains, and configure your gateway to aggressively flag external senders impersonating internal display names — Star Blizzard impersonates colleagues, so lookalike-domain and cousin-domain detection matters more than attachment sandboxing here.
Short term (1–2 weeks):
- Restrict script interpreters for standard users. Constrain
mshta.exe,wscript.exe, andcscript.exevia AppLocker or WDAC for users with no business need. PowerShell Constrained Language Mode plus script block logging (Module, ScriptBlock, and Transcription logging to a central collector) should be baseline. - Harden against rapport-building pretexts. Implement an out-of-band verification norm for event invitations: any invitation link or attachment from an external party gets confirmed via a known, previously established channel before opening. Make this an explicit, written policy for high-risk staff.
- Review cloud file-sharing access. Block or alert on access to file-hosting domains not in your approved business list from high-risk user segments.
If compromise is suspected:
- Isolate the endpoint via Defender for Endpoint (or your EDR), preserve volatile data, and pull a memory image before remediation.
- Assume identity compromise follows endpoint compromise. Revoke all sessions and refresh tokens for the affected user, reset credentials, and audit mailbox rules, OAuth grants, and MFA registrations. Star Blizzard's credential-harvesting heritage means the endpoint implant may be paired with account access.
- Report. Contact Microsoft (via your account team or MSRC), CISA (report@cisa.gov for US entities), or the NCSC (for UK entities) — both agencies have active visibility into Star Blizzard operations and can provide victim-specific IOC enrichment.
Reference advisories:
- Microsoft Threat Intelligence reporting on Star Blizzard: https://www.microsoft.com/security/blog/
- CISA/NSA/NCSC joint guidance on Star Blizzard (SEABORGIUM) activity: https://www.cisa.gov/news-events/cybersecurity-advisories (search "Star Blizzard" / "SEABORGIUM")
- MITRE ATT&CK group profile G1008 (Star Blizzard / COLDRIVER)
The strategic lesson: Star Blizzard reconstituted after a major DOJ takedown and came back delivering malware instead of just phishing credentials. Adversaries adapt faster than annual security refresh cycles. Behavior-based endpoint detection, enforced ASR rules, and a human verification culture for unexpected invitations are the controls that survive adversary evolution — because they don't depend on knowing the payload in advance.
Related Resources
Security Arsenal Alert Triage Automation AlertMonitor Platform Book a SOC Assessment platform Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.