fake-whatsapp-star-blizzard

How Russian hackers went after NGOs’ WhatsApp accounts

Share:

Star Blizzard, a threat actor tied to the Russian Federal Security Service (FSB), was spotted attempting to compromise targets’ WhatsApp accounts through a clever phishing campaign.

The campaign

The campaign started with a spear-phishing email that was made to look like it was sent by a US government official.

“We have established a private WhatsApp group to facilitate discussions regarding the latest non-govermental initiatives aimed at supporting Ukraine. This platform will also serve as a means to coordinate the distribution of government-allocated funds for this purpose,” the email says. “You can join us using this QR code below.”

The QR code doesn’t work, though, pushing the victim to reply to say as much. Then, the attackers send a second email, with a shortened link instead of a QR code.

The link leads to a spoofed WhatsApp webpage asking them to go through several steps to join the group.

The spoofed WhatsApp page, with the QR code obscured (Source: Microsoft Threat Intelligence)

“However, this QR code is actually used by WhatsApp to connect an account to a linked device and/or the WhatsApp Web portal,” Microsoft’s threat analysts explained.

“This means that if the target follows the instructions on this page, the threat actor can gain access to the messages in their WhatsApp account and have the capability to exfiltrate this data using existing browser plugins, which are designed for exporting WhatsApp messages from an account accessed via WhatsApp Web.”

About Star Blizzard

The campaign seems to have been aimed at non-governmental organization (NGO) employees and, according to Microsoft, it started in mid-November and ended by the end of the month.

Nevertheless, it shows how Star Blizzard changes its tactics, techniques, and procedures (TTPs) and persists in achieving its goals.

“Star Blizzard’s targets are most commonly related to government or diplomacy (both incumbent and former position holders), defense policy or international relations researchers whose work touches on Russia, and sources of assistance to Ukraine related to the war with Russia,” the threat analysts noted.

They’ve also been known to target Russian citizens residing in the US, UK citizens, and computer networks belonging to NATO.

In late 2024, the Microsoft and the US Justice Department seized 100+ domains used the group, ans set the stage for further disruption any new infrastructure through an existing court proceeding.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:52 pm, Jul 5, 2025
weather icon 21°C
L: 20° | H: 22°
light rain
Humidity: 73 %
Pressure: 1012 mb
Wind: 14 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0.12 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:50 am
Sunset: 9:19 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
20° | 22°°C 0.2 mm 20% 12 mph 74 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 22°°C 1 mm 100% 10 mph 82 % 1011 mb 0 mm/h
Mon Jul 07 10:00 pm
weather icon
14° | 21°°C 0.2 mm 20% 13 mph 80 % 1015 mb 0 mm/h
Tue Jul 08 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 10 mph 74 % 1020 mb 0 mm/h
Wed Jul 09 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 9 mph 50 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
20° | 21°°C 0 mm 0% 12 mph 73 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 21°°C 0.2 mm 20% 10 mph 74 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 20°°C 0 mm 0% 8 mph 77 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 17°°C 0 mm 0% 7 mph 82 % 1008 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 7 mph 79 % 1007 mb 0 mm/h
Tomorrow 10:00 am
weather icon
18° | 18°°C 0.03 mm 3% 8 mph 73 % 1006 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
19° | 19°°C 1 mm 100% 10 mph 77 % 1006 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
22° | 22°°C 0.97 mm 97% 10 mph 47 % 1005 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,640.20
0.25%
Ethereum(ETH)
€2,121.08
0.56%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.88
0.30%
Solana(SOL)
€124.06
0.26%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.138141
0.21%
Shiba Inu(SHIB)
€0.000009
1.30%
Pepe(PEPE)
€0.000008
0.82%
Scroll to Top