• WWDC 2025
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Home General App

Russian Hackers Target WhatsApp for Data on Ukraine

Akinola Ajibola by Akinola Ajibola
January 18, 2025
in App, Security
Share on FacebookShare on Twitter

A known hacking organization, according to Microsoft Corp., linked to Russia’s government has attempted to obtain WhatsApp data from employees of non-governmental organisations providing help to Ukraine. 

The Russian state-linked hackers have sent emails to government ministers and officials around the world, encouraging them to join WhatsApp user groups.

Attackers affiliated with Russia’s Federal Security Service, or FSB, sent emails to specific targets requesting that they join WhatsApp groups, Microsoft researchers said in a blog post Thursday. The phishing mails frequently seemed to be from a US government official and included a QR code that pretended to provide information about programs to support Ukraine in its continuing fight with Russia. Microsoft did not disclose whether any of the attempted hacks resulted in successful breaches.

Microsoft attributed the cyberattacks to Star Blizzard, an alleged state-backed hacking outfit. Since October, the US Justice Department has seized or taken down 180 websites affiliated with the group, according to Microsoft, headquartered in Redmond, Washington.

The WhatsApp method is a new strategy by the hacking group Star Blizzard. The National Cyber Security Centre (NCSC) of the United Kingdom has linked Star Blizzard to Russia’s internal intelligence service, the FSB, accusing it of attempting to “undermine trust in politics in the UK and likeminded states”

A representative from WhatsApp stated in a statement that the business uses end-to-end encryption to secure confidential chats and that users should only click on links from individuals they know and trust. A request for comment was not responded to promptly by the Russian Embassy in Washington.

The US Cybersecurity and Infrastructure Security Agency, or CISA, stated in December that the Star Blizzard group is “almost certainly” tied to Russia’s FSB, given the group’s history of attempting to hack American and British lawmakers, academics, and members of the defense sector. According to CISA, Star Blizzard specializes in investigating possible targets on social media, locating their professional relationships, and creating email accounts that appear to be trusted associates.

More information according to a blog post by Microsoft also revealed that users receive an email from an attacker impersonating a US government official, encouraging them to click on a QR code, which grants the attacker access to their WhatsApp account. Rather than providing access to a WhatsApp group, the code connects an account to a paired device or the WhatsApp Web page. “The threat actor can gain access to the messages in their WhatsApp account and have the capability to exfiltrate this data,” according to Microsoft!

Microsoft did not say whether data was successfully stolen from targeted WhatsApp accounts.

According to the report, the bogus email was an invitation to join a WhatsApp group discussing “the latest non-governmental initiatives aimed at supporting Ukraine NGOs.” In addition to targeting ministers and officials in unnamed nations, the effort has attempted to target those active in Russia-related diplomacy, defence strategy, and international relations research, as well as activity connected to assisting Ukraine in its battle with Russia.

In 2023, the NCSC stated that Star Blizzard had targeted British MPs, universities, and journalists, among others, in an attempt to “interfere with UK politics and democracy”. It said Star Blizzard was “almost certainly subordinate” to the FSB’s Centre 18 unit. As part of the 2023 statement, the UK sanctioned two Star Blizzard members, including an FSB officer.

Microsoft said the WhatsApp campaign looked to have ended in November, but Star Blizzard’s shift in tactics highlighted the unit’s tenacity in utilizing spear phishing – the phrase for sending malicious emails to specific persons or groups – to try to gain access to critical information. The cybersecurity community refers to the increasingly widespread technique of cybercriminals employing QR codes as “quishing”.

Microsoft advised email users in areas targeted by Star Blizzard to “always remain vigilant” when dealing with emails, especially those containing external links.

Cisa explained that Star Blizzard specializes in investigating possible targets on social media, locating their professional relationships, and creating email accounts that appear to be trustworthy associates. 

“When in doubt, contact the person you think is sending the email using a known and previously used email address to verify that the email was indeed sent by them,” according to the message.

WhatsApp, owned by Facebook’s parent company, Meta, is an end-to-end encrypted program, which means that only the sender and recipient of a message can read it, unless the user is duped into giving up access to their account.

According to a WhatsApp representative, if you want to attach your WhatsApp account to a companion device, you should only do so using WhatsApp’s officially supported services, not third-party websites. And no matter what service you’re using, only click on links from individuals you know and trust.”

Related Posts:

  • resize
    Hackers Caused A Massive Traffic Jam In Moscow
  • 53be3da0-24d3-11ee-b5fb-1b4d6ff54812.cf
    Several Sensitive U.S. Military Emails Sent To Mali…
  • whatsapp-proxy
    WhatsApp Adds Proxy Support To Bypass Restrictions…
  • app icons, social media, search _ logo, google, engine, software_md
    Google Announces Deactivation of AdSense Accounts in Russia
  • 499920413_726083126518205_4604772183644586656_n
    WhatsApp Adds Encrypted Voice Chat to All Groups
  • WA_QR_CODE_VIEW_FOLLOW_CHANNEL_FEATURE_IOS
    WhatsApp Tests QR Channel & Sticker Pack Sharing
  • Picture2
    Soon, WhatsApp Will Simplify the Process of Adding…
  • skynews-whatsapp-phone-messaging_6156083
    WhatsApp Will Let Users Lock & Hide Every Intimate…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Subscribe

Tags: hackersrussiaukrainewhatsapp
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Apple Launches EnergyKit for Smart Home Efficiency June 12, 2025
  • Multiverse Computing Raises $215M to Reduce AI Computing Costs June 12, 2025
  • Argentina, Hong Kong, and Thailand Get Threads DM First June 12, 2025
  • OpenAI to Use Google Cloud for Computing Infrastructure June 12, 2025
  • MultiChoice’s Side Projects Grow as TV Business Declines June 12, 2025
  • South African Fibre Company Announces Job Cuts June 12, 2025

Browse Archives

June 2025
MTWTFSS
 1
2345678
9101112131415
16171819202122
23242526272829
30 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
  • Login

© 2021 Design By Tech Booky Elite

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • WWDC 2025
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2021 Design By Tech Booky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Subscribe

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Ok