Security experts have discovered a new spear-phishing campaign orchestrated by Russian state-backed threat actors against high-profile diplomats and Ukrainian aid organizations. Threat actors initiate contact by masquerading as US government officials and sending fake email messages to their targets. The messages typically contain a rogue invitation to a WhatsApp group allegedly related to non-governmental initiatives supporting Ukraine. However, the initial email message prompting recipients to join the group displays a broken QR code, a technique used to force the target to reply, asking for a working alternative. Has the United States become so vulnerable to attacks ?

