FILTERING BY: CLEAR FILTER

Russian APTs Target Signal Messenger Backup Recovery Keys for Account Takeover

Russian state-sponsored APTs are conducting targeted phishing campaigns to harvest Signal Messenger backup recovery keys, bypassing established end-to-end encryption (E2EE) protocols. By utilizing sophisticated social engineering lures masquerading as official security alerts, actors target high-value demographics—specifically journalists and political activists—to facilitate complete account takeover (ATO). Once recovery keys are obtained, attackers can migrate accounts and decrypt historical chat backups stored in the cloud. The US government has signaled the severity of this intelligence-led campaign by offering a $10 million reward for information identifying the responsible actors, highlighting a pivot from protocol exploitation to targeting the human-centric recovery mechanism.

U.S. State Department Issues $10M Bounty Targeting UNC5792 and UNC4221 via Signal and WhatsApp Phishing Campaigns

The U.S. Department of State has announced a $10 million reward for actionable intelligence identifying Russian-linked threat actors UNC5792 and UNC4221. These actors focus on bypassing end-to-end encryption (E2EE) on Signal and WhatsApp through sophisticated account takeover (ATO) workflows. By utilizing advanced social engineering, credential harvesting, and session hijacking, the groups compromise mobile identities of high-value targets, including military and diplomatic personnel. The campaign targets the application layer to circumvent cryptographic protections, facilitating large-scale intelligence exfiltration from mobile endpoints. This shift toward identity-centric exploitation bypasses traditional network perimeter defenses, necessitating enhanced hardware-backed authentication and mobile-specific threat intelligence.

Russian State-Sponsored Campaign Targeting Signal Messenger Accounts

Russian state-sponsored threat actors have launched a targeted campaign to hijack Signal Messenger accounts by exploiting vulnerabilities in the Public Switched Telephone Network (PSTN) rather than the application's encryption. This shift toward identity-layer exploitation demonstrates a sophisticated strategic pivot to bypass End-to-End Encryption (E2EE) by compromising the telephony-based authentication process used for account registration.

Weaponization of Telegram, Discord, and Signal for C2 and Malware Delivery

Nation-state actors, including Iranian and Russian-linked groups, are increasingly leveraging mainstream communication platforms—specifically Telegram, Discord, and Signal—to facilitate Command and Control (C2) operations and malware delivery. By utilizing these high-reputation SaaS applications, attackers mask malicious traffic within legitimate, high-volume encrypted streams, effectively bypassing traditional Network Detection and Response (NDR) and Endpoint Detection and Response (EDR) solutions. Technical implementations include the Rust-based ChaosBot malware, which utilizes Discord’s API for corporate espionage, and various Telegram-integrated payloads. This tactical shift enables persistent C2 channels, facilitates intellectual property theft, and supports targeted surveillance of dissidents through the exploitation of trusted third-party infrastructures.


LINK COPIED TO CLIPBOARD