FILTERING BY: CLEAR FILTER

Russian APTs Target Signal Messenger Backup Recovery Keys for Account Takeover

Russian state-sponsored APTs are conducting targeted phishing campaigns to harvest Signal Messenger backup recovery keys, bypassing established end-to-end encryption (E2EE) protocols. By utilizing sophisticated social engineering lures masquerading as official security alerts, actors target high-value demographics—specifically journalists and political activists—to facilitate complete account takeover (ATO). Once recovery keys are obtained, attackers can migrate accounts and decrypt historical chat backups stored in the cloud. The US government has signaled the severity of this intelligence-led campaign by offering a $10 million reward for information identifying the responsible actors, highlighting a pivot from protocol exploitation to targeting the human-centric recovery mechanism.


LINK COPIED TO CLIPBOARD