🌟 Russian Star Blizzard Targets WhatsApp Accounts in Spear-Phishing Campaign 🚨
A new spear-phishing campaign by the Russian threat actor Star Blizzard is exploiting WhatsApp's account linking features to gain unauthorized access to victims' messages and exfiltrate data. Here’s how the attack works and what you need to know to stay safe:
🔍 How the Attack Works
1. Initial Contact via Email
The victim receives a seemingly harmless email.
If they reply, they are sent a second email apologizing for the inconvenience and asking them to click on a t[.]ly shortened link to join a WhatsApp group.
2. QR Code Trick
The shortened link redirects the victim to a website (aerofluidthermo[.]org).
On the site, the victim is instructed to scan a QR code to join the group.
Reality Check: The QR code is actually used to link the victim's WhatsApp account to the attacker’s device via WhatsApp Web or a linked device portal.
3. Data Exfiltration
Once linked, the attackers gain access to the victim’s WhatsApp messages.
They can also extract sensitive information using malicious browser add-ons.
🎯 Key Targets
Star Blizzard is known for targeting individuals in sensitive sectors. This campaign shows their adaptability and persistence, shifting tactics to bypass countermeasures.
⚠️ How to Protect Yourself
✅ Beware of Shortened Links: Avoid clicking on links, especially those using shortened URLs, from unknown senders.
✅ Verify QR Code Prompts: Only scan QR codes from trusted sources.
✅ Check Email Authenticity: Be cautious when receiving unexpected emails requesting action.
✅ Enable Two-Step Verification on WhatsApp: Add an extra layer of security to your account.
✅ Use a Secure Browser: Disable suspicious browser extensions and audit installed add-ons regularly.
Post #1565
433
- 👍 1