logo

Russian Star Blizzard hackers exploit WhatsApp accounts to spy on nonprofits aiding Ukraine

ID: 9c34d0c9-06b1-5fc3-b5ee-5d8d48449db7

STIX ID: report--9c34d0c9-06b1-5fc3-b5ee-5d8d48449db7

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-01-17

Date Updated: 2026-05-01

...
...

Star Blizzard (Callisto Group), a Russian state-linked APT, ran a mid-November phishing campaign impersonating U.S. officials to trick nonprofits supporting Ukraine into scanning malicious WhatsApp QR codes that linked victims’ accounts to attacker-controlled devices for message exfiltration; Microsoft and the DOJ have previously seized many of the group's domains, but the group adapted and shifted tactics to continue operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.