Russian APT28 Phishes Signal Backup Keys to Hijack Accounts
Key Takeaways Russian state-sponsored hackers, identified as APT28 (UNC5792 and UNC4221), are executing a sophisticated phishing campaign targeting Signal users. The attackers impersonate Signal...
Key Takeaways
- Russian state-sponsored hackers, identified as APT28 (UNC5792 and UNC4221), are executing a sophisticated phishing campaign targeting Signal users.
- The attackers impersonate Signal support to trick high-value individuals, including government officials, military personnel, and journalists, into divulging their Signal backup recovery keys.
- This social engineering tactic does not exploit a flaw in Signal’s end-to-end encryption but rather manipulates users into compromising their own accounts.
- Successful compromise allows attackers to access historical private and group chats and assume control of the victim’s Signal account.
- Users are advised to be highly skeptical of unsolicited security alerts within messaging apps and to never share recovery keys or verification codes.
Russian Intelligence Targets Signal Users with Phishing Campaign
A persistent phishing campaign, attributed to Russian intelligence services and tracked as UNC5792 and UNC4221, is actively attempting to compromise Signal accounts. The attackers are employing social engineering techniques, masquerading as legitimate Signal support personnel, to trick high-value targets into revealing their backup recovery keys. This operation represents a significant threat to individuals engaged in sensitive communications, including government officials, military personnel, political figures, journalists, and Ukrainian leaders.
Table Of Content
The campaign’s effectiveness lies in its deceptive nature, rather than any breach of Signal’s robust end-to-end encryption. However, the potential loss of private messages and account control remains a critical concern, as detailed in a recent report.
The Deception: How Attackers Obtain Signal Backup Keys
The phishing messages are crafted to create a sense of urgency, typically claiming imminent data loss due to synchronization issues with chats, media, or account information. Victims are then guided through a series of steps: navigating to backup settings, copying their unique recovery key, and subsequently pasting it directly into the deceptive chat with the fake support account.
The FBI said in a report shared with Cyber Security News (CSN) that multiple Russian Intelligence Services clusters are behind this ongoing commercial messaging application phishing activity against high-value individuals. This shift in tactics, from requesting verification codes or PINs to specifically targeting backup recovery keys, is crucial. A recovery key grants attackers access to archived content that would otherwise be inaccessible, even with Signal’s strong encryption.
Once a victim provides their recovery key, and assuming they have enabled message backups, attackers can download all historical private and group chats. Following this data exfiltration, the attackers can then seize control of the compromised Signal account. It is important to reiterate that while individual accounts are being compromised through this method, the Signal application itself and its underlying encryption protocols remain secure.
This tactic is a continuation of a pattern observed in an earlier Signal phishing campaign, exploiting the trust users place in service notifications.
Lasting Impact and Attribution
The compromise has lasting consequences. Even if a victim creates a new Signal account using the same phone number, the stolen recovery key remains valid, potentially allowing attackers to regain access at a later date. Generating a new backup recovery key in the app’s settings will invalidate the old key for future downloads, but it cannot reverse the compromise of any backup data already obtained by the attackers.
The activity is linked to officers of the Russian Federal Security Service working in conjunction with border guards, as well as individuals acting on behalf of Russian military services. These groups have a history of targeting critical communications, reminiscent of Russian attacks on telecom networks, underscoring the broader implications for operational continuity and safety beyond individual privacy.
What You Should Do
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.