logo

Russia's Star Blizzard phishing crew caught targeting WhatsApp accounts

ID: 68062af5-6c53-5055-964b-ce6ebedfcddb

STIX ID: report--68062af5-6c53-5055-964b-ce6ebedfcddb

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-01-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft reported that Star Blizzard (FSB-linked) conducted a targeted phishing campaign that lured government, diplomatic, and defense-related personnel with fake WhatsApp group invitations; the attackers used invalid QR codes to elicit responses, then sent links that led to malicious WhatsApp Web QR codes allowing session linking and exfiltration of messages via browser plugins—demonstrating an adaptive shift in TTPs after prior infrastructure takedowns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.