Star Blizzard hackers abuse WhatsApp to target high-value diplomats
ID: 2ebf1836-badf-5e4e-90d6-9a50460d26bc
STIX ID: report--2ebf1836-badf-5e4e-90d6-9a50460d26bc
Feed Name: Bleeping Computer
Microsoft observed a mid-November 2024 Star Blizzard spear-phishing campaign that impersonates U.S. officials to send broken QR-code WhatsApp invitations; when targets reply they are sent short links to a fake WhatsApp web page whose QR links attach the attacker’s device to the victim’s account, enabling access and exfiltration of messages via browser plugins. The attack uses social engineering (no malware), targets diplomats and Ukraine-related actors, and represents a tactical shift after prior domain takedowns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
