- Category
- Latest news
Russian State-Linked Hackers Launch Global WhatsApp Scam Targeting Ministers
A hacking unit called Star Blizzard, linked to the Russian state, has targeted government ministers and officials worldwide by sending emails inviting them to join WhatsApp user groups and then stealing their account data.
According to a Microsoft blog post, victims receive emails from attackers posing as US government officials. The emails entice recipients to click on a QR code, which grants the attacker access to their WhatsApp account. Instead of connecting to a WhatsApp group, the code links the victim’s account to a new device or the WhatsApp Web portal.
“The threat actor can gain access to the messages in their WhatsApp account and have the capability to exfiltrate this data,” said Microsoft.
Microsoft did not confirm if data was successfully stolen from the targeted WhatsApp accounts. The phishing emails, disguised as invitations to join a WhatsApp group supporting Ukraine NGOs, targeted ministers, diplomats, defense policy experts, and researchers involved in international relations and aid for Ukraine.
On December 19, Russian hackers targeted Ukraine’s state registries, causing a temporary shutdown of critical systems within the Ministry of Justice of Ukraine.