logo

New Star Blizzard spear-phishing campaign targets WhatsApp accounts

ID: a56feaa9-c10a-5229-99c9-af37290bfef7

STIX ID: report--a56feaa9-c10a-5229-99c9-af37290bfef7

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2025-01-16

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence reports that the Russian actor Star Blizzard shifted tactics in Oct–Nov 2024 to a spear‑phishing campaign that lures targets to scan malicious WhatsApp linking QR codes (or follow shortened links) to pair attacker-controlled WhatsApp Web sessions and exfiltrate messages; the blog describes targeting (government/diplomacy, defense/Russia researchers, Ukraine-related assistance), lists two malicious domains observed, provides mitigations, hunting queries, and detections, and notes the activity appeared limited and wound down by end of November.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.