Overview

Star Blizzard, a well-documented Russian threat actor, has pivoted to targeting WhatsApp accounts through sophisticated spear-phishing campaigns. The group leverages QR code manipulation and social engineering

Whom it may concern

  • Government officials and diplomats
  • Defense policy researchers
  • Ukraine aid organizations
  • International relations analysts

Key Findings

  1. Successfully identified and tracked new TTPs using WhatsApp
  1. Compromised 180+ domains between January 2023 and August 2024
  1. Campaign utilized broken QR codes to initiate victim engagement
  1. Microsoft successfully degraded previous infrastructure

Risk Analysis

  • Probability: High (based on historical success rate)
  • Impact: Critical for diplomatic communications
  • Potential data exfiltration via browser add-ons
  • Attack sophistication level: Advanced

Action Items

  • Implement 2FA security controls beyond WhatsApp
  • Enhance staff training on QR code security
  • Deploy additional endpoint monitoring
  • Review and update incident response procedures

Sources

  • [The Hacker News](https://thehackernews.com/2025/01/russian-star-blizzard-shifts-tactics-to.html)
Share this article

Stay up to date

Join my community and receive the latest risk news and trends.