FSB-linked Russian threat actor group "Star Blizzard" targets WhatsApp accounts of ministers
John Davies
Malloc
A new spear-phishing campaign has targeted WhatsApp accounts of government ministers and officials around the world. The campaign was undertaken by a Russian state-sponsored threat actor called Star Blizzard, and the unique cyber campaign aimed to support the country's war effort against Ukraine. The campaign started in mid-November and ended by the end of the month. It involved sending victims an email impersonating a US government official. The email enticed the victims with a fake invitation — the latest non-governmental initiatives aimed at supporting Ukraine NGOs — to join user groups on WhatsApp. The victims were asked to scan a QR code that would give them access to a WhatsApp group. Instead of giving access to a WhatsApp group, the code connects the targeted account to a linked device or the WhatsApp Web portal under the hackers' control. This gave the threat actors access to the WhatsApp messages of the ministers and government officials.
What is Star Blizzard?
Star Blizzard has been a longstanding cyber threat, primarily focusing on intelligence gathering and disinformation campaigns. In 2023, the NCSC described Star Blizzard as being “almost certainly subordinate” to the FSB's Centre 18 unit. The group has previously attacked civil society organizations, including think tanks, NGOs, and journalists, to interfere with their operations. As part of the 2023 announcement, the UK imposed sanctions on two Star Blizzard members, including an officer in the FSB. In late 2024, Microsoft and the US Justice Department seized more than 100 domains used by the group, but the group quickly adapted by shifting to new domains. Now, they have entirely changed their tactics and are compromising WhatsApp accounts via spear-phishing emails containing QR codes.
Star Blizzard's targets are most commonly related to government or diplomacy (both incumbent and former position holders), defence policy or international relations researchers whose work touches on Russia, and sources of assistance to Ukraine related to the war with Russia. They have also been known to target Russian citizens residing in the US, UK citizens, and computer networks belonging to NATO.
How does the Star Blizzard Campaign work?
The phishing campaign used by Star Blizzard involved a two-step email scheme, and in total three steps.
- The first email impersonates a US government official, a known tactic of Star Blizzard to establish credibility. The email contains a QR code that claims to direct recipients to a WhatsApp group offering updates on “non-governmental initiatives aimed at supporting Ukraine NGOs.” However, the QR code is intentionally broken, prompting the recipient to respond to the email. According to the researchers, the QR code being invalid might have been deliberate, to get the victim to reach out and ask for a new code.
- Star Blizzard followed up with a second email containing a shortened malicious link wrapped in a seemingly secure “Safe Links” format. The email contains a t[.]ly-shortened malicious link wrapped with Microsoft Safe Links to appear legitimate.
- Clicking on the link redirected victims to a phishing webpage that asked them to scan another QR code. If the target follows the instructions on this page, Star Blizzard gains access to the messages in their WhatsApp account and has the capability to exfiltrate this data using existing browser plugins, which are designed for exporting WhatsApp messages from an account accessed via WhatsApp Web.
The attack vector is relatively new, and it is believed that Star Blizzard was forced to adapt after being thoroughly analysed by the cybersecurity community. This is the first time researchers have identified a shift in Star Blizzard's longstanding tactics, techniques, and procedures (TTPs) to leverage a new access vector.
How to Safeguard yourself against Spear-Phishing and Quishing attacks
According to WhatsApp/Meta, if a person wants to link their WhatsApp account to a companion device, they should only do so by going to WhatsApp's officially supported services — and not through third-party websites. And no matter which service one is on, one should only click on links from people one knows and trusts.
To mitigate and safeguard themselves from such campaigns, organizations and individuals in the target group should:
- Exercise caution when receiving unsolicited emails, especially those containing QR codes or links to external sites.
- Verify the sender's identity by contacting them through a previously used and trusted email address or by other means.
- Enable multi-factor authentication (MFA) for WhatsApp and other sensitive accounts.
- Utilize QR code training simulations to educate employees about phishing methods.
Users are also recommended to use security and privacy apps, like our app Malloc, available on Android and iOS. Malloc helps protect against phishing threats, detects the presence of spyware and other malicious apps on phones, scans the phone for security vulnerabilities and root access and alerts users, blocks trackers and insecure HTTP traffic, and comes with a VPN to help users stay private online. It detects and reduces risk; it does not guarantee that every phishing attempt is stopped. More on protecting high-risk individuals and our VIP protections.
References: The Guardian — Russian hackers target WhatsApp accounts of ministers worldwide; Help Net Security — How Russian hackers went after NGOs' WhatsApp accounts.
Relevant tags:
Published on Medium