fake-whatsapp-star-blizzard

How Russian hackers went after NGOs’ WhatsApp accounts

Teilen:

Star Blizzard, a threat actor tied to the Russian Federal Security Service (FSB), was spotted attempting to compromise targets’ WhatsApp accounts through a clever phishing campaign.

The campaign

The campaign started with a spear-phishing email that was made to look like it was sent by a US government official.

“We have established a private WhatsApp group to facilitate discussions regarding the latest non-govermental initiatives aimed at supporting Ukraine. This platform will also serve as a means to coordinate the distribution of government-allocated funds for this purpose,” the email says. “You can join us using this QR code below.”

The QR code doesn’t work, though, pushing the victim to reply to say as much. Then, the attackers send a second email, with a shortened link instead of a QR code.

The link leads to a spoofed WhatsApp webpage asking them to go through several steps to join the group.

The spoofed WhatsApp page, with the QR code obscured (Source: Microsoft Threat Intelligence)

“However, this QR code is actually used by WhatsApp to connect an account to a linked device and/or the WhatsApp Web portal,” Microsoft’s threat analysts explained.

“This means that if the target follows the instructions on this page, the threat actor can gain access to the messages in their WhatsApp account and have the capability to exfiltrate this data using existing browser plugins, which are designed for exporting WhatsApp messages from an account accessed via WhatsApp Web.”

About Star Blizzard

The campaign seems to have been aimed at non-governmental organization (NGO) employees and, according to Microsoft, it started in mid-November and ended by the end of the month.

Nevertheless, it shows how Star Blizzard changes its tactics, techniques, and procedures (TTPs) and persists in achieving its goals.

“Star Blizzard’s targets are most commonly related to government or diplomacy (both incumbent and former position holders), defense policy or international relations researchers whose work touches on Russia, and sources of assistance to Ukraine related to the war with Russia,” the threat analysts noted.

They’ve also been known to target Russian citizens residing in the US, UK citizens, and computer networks belonging to NATO.

In late 2024, the Microsoft and the US Justice Department seized 100+ domains used the group, ans set the stage for further disruption any new infrastructure through an existing court proceeding.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:05 am, März 12, 2025
Wetter-Symbol 7°C
L: 6° | H: 8°
broken clouds
Luftfeuchtigkeit: 72 %
Druck: 1004 mb
Wind: 8 mph NW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:21 am
Sonnenuntergang: 5:59 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
6° | 8°°C 0.2 mm 20% 9 mph 85 % 1003 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 7°°C 0.89 mm 89% 9 mph 96 % 1007 mb 0.22 mm/h
Fr. März 14 9:00 pm
Wetter-Symbol
1° | 8°°C 0.2 mm 20% 8 mph 89 % 1015 mb 0 mm/h
Sa. März 15 9:00 pm
Wetter-Symbol
2° | 8°°C 0.2 mm 20% 14 mph 82 % 1025 mb 0 mm/h
So. März 16 9:00 pm
Wetter-Symbol
4° | 9°°C 0 mm 0% 12 mph 71 % 1027 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 7°°C 0 mm 0% 6 mph 72 % 1003 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 9 mph 65 % 1003 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 7 mph 67 % 1002 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0.2 mm 20% 9 mph 85 % 1003 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 81 % 1003 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 7 mph 86 % 1002 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
2° | 2°°C 0.2 mm 20% 6 mph 96 % 1002 mb 0.2 mm/h
Tomorrow 9:00 am
Wetter-Symbol
3° | 3°°C 0.2 mm 20% 9 mph 76 % 1003 mb 0.22 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,565.90
0.84%
Ethereum(ETH)
€1,740.52
-1.21%
Fesseln(USDT)
€0.92
0.01%
XRP(XRP)
€2.00
1.45%
Solana(SOL)
€113.94
-0.04%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.152484
2.85%
Shiba Inu(SHIB)
€0.000011
3.71%
Pepe(PEPE)
€0.000005
7.13%
Nach oben scrollen