FBI, CISA Warn of Russian APT Exploiting Signal Zero-Day
Key Takeaways Russian state-sponsored actors are conducting a large-scale phishing campaign targeting Signal users. The attackers aim to compromise high-value targets, including U.S. government...
Key Takeaways
- Russian state-sponsored actors are conducting a large-scale phishing campaign targeting Signal users.
- The attackers aim to compromise high-value targets, including U.S. government officials, military personnel, politicians, and journalists, by hijacking accounts.
- This campaign exploits social engineering tactics to bypass Signal’s end-to-end encryption, tricking users into revealing SMS verification codes or scanning malicious QR codes.
- Thousands of Signal accounts globally have reportedly been compromised.
- Users are urged to enable robust security practices and remain vigilant to prevent account takeovers.
FBI, CISA Issue Joint Warning on Russian APT Signal Exploitation
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have released a joint cybersecurity advisory, alerting the public to an extensive phishing operation. This campaign, attributed to Russian Intelligence Services, specifically targets users of encrypted messaging applications, with a primary focus on Signal.
Table Of Content
Instead of attempting to break Signal’s robust end-to-end encryption protocols, the threat actors are employing sophisticated social engineering techniques to gain unauthorized access to user accounts. This approach allows them to bypass the platform’s core security mechanisms by manipulating individuals into surrendering control of their profiles.
High-Value Targets Identified in Cyber Espionage Campaign
This cyber espionage initiative is meticulously crafted to compromise individuals deemed to possess significant intelligence value. The Russian threat actors are specifically targeting current and former U.S. government officials, military personnel, influential political figures, and prominent journalists.
According to intelligence agencies, this operation has already led to the unauthorized access of thousands of accounts on a global scale. The attackers leverage the trust associated with official communication channels to trick victims.
Social Engineering Tactics and Account Takeover Mechanics
Given that Signal’s underlying encryption remains secure, the success of this operation hinges entirely on deceptive social engineering. Attackers initiate contact by sending in-app messages designed to impersonate legitimate automated support channels. These fraudulent profiles often adopt names such as “Signal Security Support ChatBot” or “Signal Security Team” to lend an air of authenticity.
The messages are designed to create a false sense of urgency, typically by claiming that a user’s account has suffered a data leak or that suspicious login attempts from unrecognized devices or foreign locations have been detected. To “resolve” these fabricated issues, victims are then instructed to complete a “mandatory verification procedure,” which involves either sharing an SMS verification code or scanning a malicious QR code.
When a user unwittingly provides their verification code, the attackers exploit Signal’s linked device feature. This enables them to connect their own hardware to the compromised account without immediately alerting the victim. Once access is gained, the threat actors can covertly monitor private conversations, read historical messages, and infiltrate private group chats. Furthermore, they can harvest contact lists and impersonate the compromised user to launch subsequent phishing attacks against their trusted contacts.
What You Should Do
- Never Share Verification Codes: Legitimate support staff will never ask for your SMS verification codes or personal PINs via direct messages. Treat any such request as a phishing attempt.
- Exercise Caution with Security Alerts: Be extremely wary of unexpected security alerts, especially those creating a sense of urgency. Do not scan unsolicited QR codes or click unverified links from unknown or suspicious contacts.
- Regularly Audit Linked Devices: Periodically check the “Linked devices” section within your Signal settings. Immediately disconnect any unfamiliar or unauthorized hardware.
- Enable Disappearing Messages: Activate the disappearing messages feature for sensitive conversations. This automatically purges messages after a set time, minimizing the data available if an account is compromised.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.