Microsoft has uncovered a cyber-campaign orchestrated by a Russian state-sponsored threat actor known as Star Blizzard aimed at supporting Russia’s efforts in the Ukraine-Russia war. The group is targeting WhatsApp accounts belonging to diplomats, government officials, and researchers focusing on defense and international relations related to the conflict. The attack involves phishing emails with QR codes that, when scanned, link the victim’s WhatsApp account to a device controlled by the attackers, allowing for potential data exfiltration. Microsoft advises users to remain cautious of emails containing external links and to stay vigilant against such phishing attempts. This shift in tactics by Star Blizzard demonstrates a new access vector for cyber threats, signaling the need for heightened cybersecurity measures.