Visualização normal

Antes de ontemSecurity Affairs
  • ✇Security Affairs
  • U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks Pierluigi Paganini
    The U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists. The U.S. government is offering rewards of up to $10 million for information leading to the identification of members of the Russian-linked groups UNC5792 and UNC4221. The hackers target government officials, military personnel, journalists, and political figures through phishing attacks on Signal and WhatsApp. U.S. agencies warn the groups have evolved their
     

U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks

29 de Junho de 2026, 18:49

The U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists.

The U.S. government is offering rewards of up to $10 million for information leading to the identification of members of the Russian-linked groups UNC5792 and UNC4221.

The hackers target government officials, military personnel, journalists, and political figures through phishing attacks on Signal and WhatsApp. U.S. agencies warn the groups have evolved their tactics and now trick victims into revealing Signal Backup Recovery Keys, giving them access to past conversations and account data.

“Rewards for Justice is offering a reward of up to $10 million for information leading to the identification or location of any person who, while acting at the direction or under the control of a foreign government, participates in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act.” reads the announcement published by the US Government.

The attackers rely on social engineering rather than breaking encryption. They abuse legitimate device-linking features in secure messaging apps such as Signal to trick victims into connecting an attacker-controlled device to their accounts.

Once they have gained access to the target’s account, they can read sensitive conversations, access contact lists and group chats, and use the compromised account to launch new phishing attacks. In some cases, the hackers modified legitimate Signal group invite pages to redirect users to malicious links.

According to U.S. authorities, these tactics have already compromised thousands of messaging accounts.

“Targets of this cyber scheme include U.S. government officials, diplomatic personnel and foreign affairs officials, defense and national security personnel, policy analysts and advisors, NATO member-state officials and diplomats, allied intelligence and defense partners, investigative journalists covering Russia, Ukraine, and international affairs, non-governmental organizations providing support and assistance to Ukraine, and academic researchers in security studies and Russian affairs.” continues the announcement.

The U.S. Rewards for Justice program is seeking information that could identify members of UNC5792 and expose how the group operates. Authorities are interested in the hackers’ identities, their links to Russian intelligence, supporting personnel and contractors, the infrastructure and tools used in attacks, as well as the financial networks, bank accounts, cryptocurrency wallets, and funding sources that sustain the group’s operations.

This week, the FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys.

The March warning covered FSB-linked groups targeting government officials, military personnel, journalists, and Ukrainian officials through fake Signal support messages. The June update gives those groups public tracking names: UNC5792 and UNC4221, both linked to Russian Federal Security Service officers including those embedded with FSB Border Guards and others working on behalf of Russian military services.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Signal)

  • ✇Security Affairs
  • SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel Pierluigi Paganini
    Ukraine’s SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years. The Security Service of Ukraine (SSU), working jointly with the FBI, has formally exposed a sustained Russian intelligence campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The operation is ongoing. The goal isn’t disruption; it’s intelligence collection.
     

SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel

29 de Junho de 2026, 05:57

Ukraine’s SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years.

The Security Service of Ukraine (SSU), working jointly with the FBI, has formally exposed a sustained Russian intelligence campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States.

The operation is ongoing. The goal isn’t disruption; it’s intelligence collection.

“Cyber ​​experts of the Security Service of Ukraine together with the Federal Bureau of Investigation exposed Russian special services in systematic cyberattacks on messengers of officials, military personnel, politicians and activists from Ukraine, Europe and the USA.” read the alert by SSU.

“The purpose of these ‘hacks’ is to gain access to sensitive information of a military, political and economic nature that was exchanged between users, as well as to steal their personal data.”

The attack method is low-tech by design. Operators send SMS messages impersonating platform support bots, asking targets to hand over account credentials, confirmation codes, PINs, or account recovery keys. The SBU notes that these messages tend to arrive in the morning hours, when targets are physically and emotionally less guarded. Timing is a social engineering choice, not an accident.

The scope is broader than most people assume.

“The SBU emphasizes that Russian special services and hackers associated with them attack not only organizations, officials or public figures, but also personal accounts of Ukrainians.” continues the alert.

This isn’t a targeted elite program. It’s a mass collection operation with a tiered approach: high-value targets get more sophisticated techniques, ordinary citizens get the SMS impersonation play. The SBU didn’t attribute the campaign to a specific group by name, but prior reporting from Google, the FBI, and CISA ties similar activity to clusters tracked as UNC5792 and UNC4221, both linked to FSB operations, as well as Star Blizzard.

The FBI’s June 26 advisory added a new technique to what the March warning described. Russian operators have evolved from chasing one-time verification codes to specifically targeting Signal Backup Recovery Keys, which unlock an account’s entire message history and remain valid even if the user creates a new account with the same phone number afterward. This is a meaningful escalation: a stolen verification code expires, a stolen Recovery Key doesn’t.

QR codes are another active vector the SBU specifically calls out. Scanning a QR code received from an unknown bot or user can silently link the attacker’s device to the victim’s account, a technique Google’s Threat Intelligence Group documented against Signal’s linked-devices feature in early 2025.

“Russian hackers use a variety of tools and methods for such cyberattacks. For example, to extract passwords to an account, the enemy most often uses SMS messages on behalf of ‘support teams.'” states SSU.

The variety matters: blocking one delivery mechanism doesn’t stop the campaign, because the operators rotate techniques and targeting lists continuously.

The SBU’s practical guidance covers the basics that still fail most users in practice. Check active sessions in your messenger regularly and end anything you don’t recognize. Enable two-factor authentication with a complex alphanumeric PIN, not a four-digit code. Never provide confirmation codes, PINs, passwords, or recovery keys to anyone, regardless of how legitimate the request appears. Don’t scan QR codes from unknown sources. Don’t follow suspicious links even from accounts you know, because that account may already be compromised. Anyone who receives a suspicious message in a messenger can report it to the SBU’s Cybersecurity Situation Center at incident@dis.gov.ua.

Last week, the FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Ukraine)

  • ✇Security Affairs
  • New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages Pierluigi Paganini
    FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys. The March warning covered FSB-linked groups targeting government officials,
     

New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages

27 de Junho de 2026, 13:08

FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover.

The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys.

The March warning covered FSB-linked groups targeting government officials, military personnel, journalists, and Ukrainian officials through fake Signal support messages. The June update gives those groups public tracking names: UNC5792 and UNC4221, both linked to Russian Federal Security Service officers including those embedded with FSB Border Guards and others working on behalf of Russian military services.

“RIS cyber threat actors have compromised individual CMA accounts, but not the CMA’s encryption or the application itself. To date, this activity has been publicly tracked as UNC5792 and UNC4221.” reads the PSA alert published by the FBI.. “RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims’ Backup Recovery Keys.”

The earlier version of this campaign asked targets for SMS verification codes, account PINs, or tricked them into clicking doctored group invite links that silently linked an attacker’s device to the account. The new version is more damaging. The phishing message walks the target step by step through enabling Signal backups, navigating to the Recovery Key, and pasting it into the chat. Two sample messages are printed in the advisory: one dressed as a mandatory two-factor rollout announcement, the other as an urgent data recovery warning claiming messages are at risk of permanent loss.

The Recovery Key is what makes this particularly serious.

“RIS cyber threat actors continue to elicit victims’ verification codes and account PINs (see Figure 1). If a targeted user backs up their CMA messages as directed in Figure 1 and later provides their Backup Recovery Key (see Figure 2), RIS cyber threat actors can view the account’s historical messages, private and group messages, and take over the victim’s account.” continues the alert.

A backup recovery key doesn’t just unlock one session. It unlocks the entire message archive, and unlike a stolen code that expires, this key keeps working.

“If a victim inadvertently shares their Backup Recovery Key, that same key remains valid even if they create a new account following the compromise using the same phone number.” continues the report. “Consequently, the actor could potentially use the compromised key to take over the new account in the future as well.”

Making a new account doesn’t help if the old key still works against it. The only fix is generating a new key through Settings, which invalidates the old one for future backup downloads. That doesn’t recover anything the attacker already pulled, and the advisory is clear about that.

The FBI and CISA are unambiguous on one point that tends to get lost in coverage of these incidents: none of this breaks Signal’s encryption or the application itself. The attackers aren’t cracking anything. They’re walking through a legitimate feature with a key the user handed them, which is a completely different problem with a completely different solution.

Alongside the advisory, the State Department’s Rewards for Justice program announced it’s offering up to $10 million for information on UNC5792. The activity overlaps with warnings issued earlier this year by Dutch intelligence, Germany’s BfV and BSI, and France’s ANSSI, and it builds on Google Threat Intelligence Group’s documentation of UNC5792 abusing Signal’s linked-device feature in early 2025. The same tradecraft has since been observed against WhatsApp and Telegram.

For anyone using Signal who works in government, security, journalism, or military-adjacent roles, the advisory’s guidance is direct. Treat any in-app message claiming to be Signal support as hostile: real support doesn’t contact users inside the app to ask for codes, PINs, or Recovery Keys.

Open Settings, check Linked Devices, remove anything unrecognized. If you think you handed over your Recovery Key at any point, generate a new one now and assume anything backed up before that moment is already in someone else’s possession.

The encryption holds. The account is the weak point, and the advisory makes clear that the targeting is deliberate, sustained, and still active.

“To mitigate this risk, the user must generate a new Backup Recovery Key within the Settings control; this action will invalidate the previous key for all future backup downloads. However, please note that this does not prevent the actor from having already downloaded a backup of the original account.” concludes the alert.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

❌
❌