logo

WhatsApp spear phishing campaign uses QR codes to add device

ID: 38d926e6-c6bd-5547-bc87-29f1af7d46f7

STIX ID: report--38d926e6-c6bd-5547-bc87-29f1af7d46f7

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-01-17

Date Updated: 2026-04-28

...
...

Microsoft details a Russia-linked group called Star Blizzard (aka Coldriver) running a spear-phishing campaign against journalists, think-tank members, and NGO staff by using staged relationships and QR-code based lures; targets are first engaged via impersonation, then sent a broken QR to prompt a reply and subsequently a shortened link to a second QR that—if followed—adds an extra device to the victim's WhatsApp account, enabling the attackers to read messages and export conversations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.