FBI and CISA Flag Russian Cyber Operations Targeting Select Individuals via Signal
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint cybersecurity advisory concerning a widespread phishing campaign. The advisory highlights that Russian Intelligence Services are…
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint cybersecurity advisory concerning a widespread phishing campaign. The advisory highlights that Russian Intelligence Services are actively targeting users of encrypted messaging applications, particularly Signal.
The attackers are circumventing the platform's end-to-end encryption by hijacking user accounts instead of compromising the cryptographic protocols themselves.
FBI and CISA: Russian Cyber Operations
The cyber espionage campaign is aimed at individuals with significant intelligence value. The primary targets include current and former United States government officials, military personnel, influential political figures, and prominent journalists. The operation has reportedly resulted in unauthorized access to thousands of accounts globally.
Despite Signal's core encryption remaining intact, attackers employ sophisticated social engineering techniques to manipulate victims into surrendering control of their profiles. The attackers send in-app messages impersonating official support channels, using names such as "Signal Security Support ChatBot" or "Signal Security Team" to appear legitimate.
The advisory highlights that Russian Intelligence Services are actively targeting users of encrypted messaging applications, particularly Signal.
The messages create a false sense of urgency, alleging data leaks or suspicious login attempts from foreign locations. Victims are then instructed to complete a verification procedure by providing their SMS verification code or scanning a malicious QR code.
Upon obtaining the verification code, attackers exploit the application's linked device feature to tether their hardware to the compromised account. This enables them to monitor private conversations, read historical messages, and infiltrate private group chats. Additionally, they can harvest contact lists and impersonate the victim to initiate further phishing campaigns.
The FBI and CISA recommend several measures to protect against these account takeover attempts:
Do not share verification codes or personal PINs with anyone. Legitimate support staff will never request authentication codes via direct messages. Treat unexpected security alerts with caution, avoiding unsolicited QR codes or unverified links. Regularly audit the linked devices menu within application settings to identify and disconnect unauthorized hardware. Enable the disappearing messages feature to automatically delete sensitive conversations after a set time limit.
Based on reporting by GBHackers.
