Overview
Star Blizzard, a well-documented Russian threat actor, has pivoted to targeting WhatsApp accounts through sophisticated spear-phishing campaigns. The group leverages QR code manipulation and social engineering
Whom it may concern
- Government officials and diplomats
- Defense policy researchers
- Ukraine aid organizations
- International relations analysts
Key Findings
- Successfully identified and tracked new TTPs using WhatsApp
- Compromised 180+ domains between January 2023 and August 2024
- Campaign utilized broken QR codes to initiate victim engagement
- Microsoft successfully degraded previous infrastructure
Risk Analysis
- Probability: High (based on historical success rate)
- Impact: Critical for diplomatic communications
- Potential data exfiltration via browser add-ons
- Attack sophistication level: Advanced
Action Items
- Implement 2FA security controls beyond WhatsApp
- Enhance staff training on QR code security
- Deploy additional endpoint monitoring
- Review and update incident response procedures
Sources
- [The Hacker News](https://thehackernews.com/2025/01/russian-star-blizzard-shifts-tactics-to.html)