Russian State-Sponsored Hackers Target Over 100 Organizations with Fake Event Invites to Deploy Backdoor
Russian state-sponsored hacking group, Star Blizzard, has been employing fake event invitations to trick individuals into installing a backdoor on their Windows computers. According to Microsoft, these campaigns have targeted over 100 organizations, primarily in the U.S. and U.K., since January. The attacks are aimed at entities and individuals connected to Ukraine. While at least one computer has been infected, the total number of breached organizations remains undisclosed. The group, believed to be operating under Center 18 of Russia's Federal Security Service (FSB), has a history of stealing email passwords by impersonating known contacts. This year, they have expanded their tactics to include sophisticated campaigns using compromised WordPress and cPanel websites for email accounts, a shift from their previous reliance on free email services. One notable campaign in March involved Atlantic Council-themed invitations, which, if a target replied, led to a link for an iPhone exploit kit called DarkSword, ...