Russian criminal gang Star Blizzard found hitting WhatsApp accounts

A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
(Image credit: Shutterstock / AdemAY)

  • Microsoft observed Star Blizzard engaging in spear-phishing attack
  • The group is going after WhatsApp accounts of diplomats and government workers engaged in the Ukraine-Russia war
  • The phishing attack uses QR codes

A Russian state-sponsored threat actor has been spotted engaging in a unique cyber-campaign aimed at supporting the country’s war effort against Ukraine.

Researchers from Microsoft Threat Intelligence revealed the Star Blizzard group was recently seen phishing for WhatsApp accounts belonging to diplomats, government officials, defense policy or international relations researchers, and others who, in any capacity, work on the Russia - Ukraine war.

The campaign most likely started in mid-November 2024, with Microsoft warning all users always remain vigilant when dealing with email, especially those containing links to external resources.

Exfiltrating WhatsApp data

The attack starts with an email impersonating a US government official. The body of the email discusses the latest non-governmental initiatives aimed at supporting Ukraine NGOs, and provides a QR code for a private WhatsApp group talking about these matters.

The QR code is invalid, the researchers said, speculating that this might have been deliberate, to get the victim to reach out and ask for a new code. The follow-up email then provides a Safe Link wrapped t[.]ly shortened link that leads to a website with a separate QR code. This one, however, connects the WhatsApp account to a separate device, owned by the attackers.

"This means that if the target follows the instructions on this page, the threat actor can gain access to the messages in their WhatsApp account and have the capability to exfiltrate this data using existing browser plugins, which are designed for exporting WhatsApp messages from an account accessed via WhatsApp Web,” Microsoft’s researchers said in their write-up.

The attack vector is relatively new, they added, speculating that Star Blizzard was forced to adapt after being thoroughly analyzed by the cybersecurity community: "This is the first time we have identified a shift in Star Blizzard's longstanding tactics, techniques, and procedures (TTPs) to leverage a new access vector," Redmond concluded.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
Russia
Major Russian hacking group shifts focus to US and UK targets
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
WhatsApp China VPN
Paragon spyware campaign targeting journalists disrupted by WhatsApp
Trojan
WhatsApp patches security flaw which let hackers install spyware
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
A Lego Pikachu tail next to a Pebble OS watch and a screenshot of Assassin's Creed Shadow
ICYMI: the week's 7 biggest tech stories from LG's excellent new OLED TV to our Assassin's Creed Shadow review
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models