Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI Phishing Steals Browser Sessions Without Malware
July 29, 2026
macOS ClickFix Vulnerability Exploited to Deploy Atomic Stealer
July 29, 2026
Critical NVIDIA BlueField Vulner2 Vulnerability Allows Code Execution
July 29, 2026
Home/CyberSecurity News/Russian APT28 Phishes Signal Backup Keys to Hijack Accounts
CyberSecurity News

Russian APT28 Phishes Signal Backup Keys to Hijack Accounts

Key Takeaways Russian state-sponsored hackers, identified as APT28 (UNC5792 and UNC4221), are executing a sophisticated phishing campaign targeting Signal users. The attackers impersonate Signal...

Jennifer sherman
Jennifer sherman
July 29, 2026 3 Min Read
3 0

Key Takeaways

  • Russian state-sponsored hackers, identified as APT28 (UNC5792 and UNC4221), are executing a sophisticated phishing campaign targeting Signal users.
  • The attackers impersonate Signal support to trick high-value individuals, including government officials, military personnel, and journalists, into divulging their Signal backup recovery keys.
  • This social engineering tactic does not exploit a flaw in Signal’s end-to-end encryption but rather manipulates users into compromising their own accounts.
  • Successful compromise allows attackers to access historical private and group chats and assume control of the victim’s Signal account.
  • Users are advised to be highly skeptical of unsolicited security alerts within messaging apps and to never share recovery keys or verification codes.

Russian Intelligence Targets Signal Users with Phishing Campaign

A persistent phishing campaign, attributed to Russian intelligence services and tracked as UNC5792 and UNC4221, is actively attempting to compromise Signal accounts. The attackers are employing social engineering techniques, masquerading as legitimate Signal support personnel, to trick high-value targets into revealing their backup recovery keys. This operation represents a significant threat to individuals engaged in sensitive communications, including government officials, military personnel, political figures, journalists, and Ukrainian leaders.

Table Of Content

  • Key Takeaways
  • Russian Intelligence Targets Signal Users with Phishing Campaign
  • The Deception: How Attackers Obtain Signal Backup Keys
  • Lasting Impact and Attribution
  • What You Should Do

The campaign’s effectiveness lies in its deceptive nature, rather than any breach of Signal’s robust end-to-end encryption. However, the potential loss of private messages and account control remains a critical concern, as detailed in a recent report.

The Deception: How Attackers Obtain Signal Backup Keys

The phishing messages are crafted to create a sense of urgency, typically claiming imminent data loss due to synchronization issues with chats, media, or account information. Victims are then guided through a series of steps: navigating to backup settings, copying their unique recovery key, and subsequently pasting it directly into the deceptive chat with the fake support account.

The FBI said in a report shared with Cyber Security News (CSN) that multiple Russian Intelligence Services clusters are behind this ongoing commercial messaging application phishing activity against high-value individuals. This shift in tactics, from requesting verification codes or PINs to specifically targeting backup recovery keys, is crucial. A recovery key grants attackers access to archived content that would otherwise be inaccessible, even with Signal’s strong encryption.

Once a victim provides their recovery key, and assuming they have enabled message backups, attackers can download all historical private and group chats. Following this data exfiltration, the attackers can then seize control of the compromised Signal account. It is important to reiterate that while individual accounts are being compromised through this method, the Signal application itself and its underlying encryption protocols remain secure.

This tactic is a continuation of a pattern observed in an earlier Signal phishing campaign, exploiting the trust users place in service notifications.

Lasting Impact and Attribution

The compromise has lasting consequences. Even if a victim creates a new Signal account using the same phone number, the stolen recovery key remains valid, potentially allowing attackers to regain access at a later date. Generating a new backup recovery key in the app’s settings will invalidate the old key for future downloads, but it cannot reverse the compromise of any backup data already obtained by the attackers.

The activity is linked to officers of the Russian Federal Security Service working in conjunction with border guards, as well as individuals acting on behalf of Russian military services. These groups have a history of targeting critical communications, reminiscent of Russian attacks on telecom networks, underscoring the broader implications for operational continuity and safety beyond individual privacy.

What You Should Do

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackHackerphishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Ruflo MCP Bridge Flaw Lets Attackers Hijack AI Agents

Next Post

Critical NVIDIA BlueField Vulner2 Vulnerability Allows Code Execution

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Flaw in Joyfill npm Packages Lets Attackers Deploy RAT and Steal Credentials
July 29, 2026
Critical Tor Browser Bug Lets Attackers Hijack Users
July 29, 2026
Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism
July 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us