logo

Microsoft catches Russian state-sponsored hackers shifting tactics to WhatsApp

ID: 3a52db96-6e21-5a07-b375-28bcc4f67830

STIX ID: report--3a52db96-6e21-5a07-b375-28bcc4f67830

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2025-01-16

Date Updated: 2026-04-21

Author: Greg Otto

...
...

Microsoft published intelligence that Star Blizzard, an FSB-linked APT, adapted its TTPs in mid-November 2024 to phish WhatsApp account sessions by sending emails with broken QR codes and follow-up shortened links leading to phishing pages that abuse WhatsApp Web’s QR account-linking feature; the campaign targeted government, diplomatic, defense-policy researchers and civil society actors and reportedly stopped at the end of November.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.