SSU and FBI Expose Russian Intelligence Signal Phishing Operation
Ukraine's SSU and the FBI uncovered a Russian cyber-espionage campaign using SMS phishing to steal Signal backup recovery keys from global targets.
The Security Service of Ukraine (SSU) and the U.S. Federal Bureau of Investigation (FBI) have jointly exposed a systematic cyber-espionage campaign orchestrated by Russian intelligence services, targeting high-value individuals globally.
The campaign heavily utilized advanced social engineering tactics via SMS and messaging applications. Attackers masqueraded as official support bots for platforms such as Signal, WhatsApp, and Telegram, sending urgent messages designed to trick users into disclosing sensitive account credentials and verification codes.
Targeting Backup Recovery Keys
While early stages of the operation focused on stealing one-time PINs, authorities warned that the attackers had escalated their methods to specifically target Signal Backup Recovery Keys. Compromising these keys allows threat actors to decrypt a victim's entire message history and maintain persistent access across devices.
The campaign, linked to Russian threat clusters UNC5792 and UNC4221, targeted government officials, military personnel, journalists, and activists, though ordinary citizens were also caught in the dragnet.
Executive Action
Organizations must mandate regular reviews of active messaging sessions, enforce strong PIN codes, and train personnel to never share verification codes or Recovery Keys, even with purported official support channels.
Join the Tech Bytes Newsletter
Get the absolute latest deeply analytical tech insights delivered to your inbox every morning.