- Microsoft observed that Star Blizzard was involved in spear-phishing attacks
- The group is going after WhatsApp accounts of diplomats and government workers engaged in the war between Ukraine and Russia
- The phishing attack uses QR codes
A Russian state-sponsored threat actor has been seen engaging in a unique cyber campaign aimed at supporting the country’s war effort against Ukraine.
Microsoft Threat Intelligence researchers revealed that the Star Blizzard group was recently seen phishing for WhatsApp accounts belonging to diplomats, government officials, defense policy or international relations researchers, and others working in any capacity on the Russia-Ukraine war.
The campaign most likely started in mid-November 2024, with Microsoft warning that all users should always remain vigilant when handling email, especially those containing links to external resources.
Exfiltrating WhatsApp data
The attack starts with an email impersonating a US official. The body of the email discusses recent non-governmental initiatives aimed at supporting Ukraine’s NGOs and provides a QR code for a private WhatsApp group discussing these issues.
The QR code is invalid, the researchers said, speculating that this could have been deliberate, to get the victim to reach out and ask for a new code. The follow-up email then provides a secure link wrapped[.]shortened link leading to a website with a separate QR code. However, this one connects the WhatsApp account to a separate device owned by the attackers.
“This means that if the target follows the instructions on this page, the threat actor can access the messages on their WhatsApp account and have the ability to exfiltrate that data using existing browser plugins designed to export WhatsApp messages from an account is accessed via WhatsApp Web,” Microsoft researchers said in their write-up.
The attack vector is relatively new, they added, speculating that Star Blizzard was forced to adapt after being thoroughly analyzed by the cybersecurity community: “This is the first time we have identified a shift in Star Blizzard’s long-standing tactics, techniques and procedures ( TTPs) ) to exploit a new access vector,” Redmond concluded.