216.73.216.6

New Star Blizzard spear-phishing campaign targets WhatsApp accounts

· Published 17/01/2025 15:15 · Modified 17/01/2025 15:23

Export JSON

Essential information

Published
17/01/2025 15:15
Modified
17/01/2025 15:23
Tags
2025-01-17 credential-theft diplomacy targets government targets qr code russian threat actor social engineering spear-phishing whatsapp
Related entities
2 observables, 1 intrusion sets (apt), 10 techniques (mitre), 6 others

Description

Star Blizzard, a , has launched a new campaign targeting accounts. The campaign, observed in mid-November 2024, marks a shift in the actor's tactics. Targets include government officials, diplomats, and researchers focused on Russia-related topics. The attack involves sending emails with broken QR codes, followed by malicious links that trick victims into granting access to their accounts. This change in strategy is likely a response to previous exposures of their tactics. The campaign, while limited, demonstrates the actor's persistence in seeking sensitive information despite operational disruptions. Microsoft recommends vigilance when dealing with emails containing external links, especially for those in sectors typically targeted by Star Blizzard.

External references