Russian state-sponsored threat actors have launched a targeted campaign to hijack Signal Messenger accounts by exploiting vulnerabilities in the Public Switched Telephone Network (PSTN) rather than the application's encryption. This shift toward identity-layer exploitation demonstrates a sophisticated strategic pivot to bypass End-to-End Encryption (E2EE) by compromising the telephony-based authentication process used for account registration.
-
Incident Discovery: Telemetry and Defensive Observation
- Proactive Researcher Monitoring: The campaign was identified by a prominent spyware researcher who utilized custom telemetry to monitor registration attempts on their personal Signal account, detecting an anomalous surge in unauthorized requests.
- Attacker-Side Metadata Capture: By maintaining a "honey-token" style posture, the researcher was able to capture critical technical artifacts from the attackers' failed attempts to bind a phone number to an unauthorized device instance.
- Pattern Analysis of Registration Flows: Forensic analysis revealed that the registration attempts were not random but followed a highly coordinated sequence of rapid-fire requests, deviating sharply from standard user behavior and indicating automation.
- Identification of Operational Footprints: The ability to intercept failed registration handshakes allowed for the mapping of the attacker's initial infrastructure, providing indicators of compromise (IoCs) that linked the activity to known state-level patterns.
-
Attack Vector: Telephony and Identity Layer Exploitation
- PSTN Vulnerability Leverage: Attackers exploited the fundamental reliance of secure messaging platforms on the Public Switched Telephone Network (PSTN), specifically the systemic insecurity of SMS-based identity verification.
- Orchestrated SIM Swapping: The campaign utilized sophisticated SIM swapping techniques, combining social engineering of mobile carrier employees with technical SMS interception to hijack the target's telephony identity.
- Registration State Manipulation: Threat actors attempted to manipulate the Signal registration state machine, seeking to exploit the temporal gap between the arrival of an SMS verification code and the final binding of the account to a new device.
- Social Engineering Frameworks: Analysis revealed the use of highly tailored phishing templates designed to trick both the end-user and telecommunications support staff into releasing single-use verification codes.
-
Threat Actor Attribution: Russian Intelligence Correlation
- TTP Mapping to GRU/SVR: The tactics, techniques, and procedures (TTPs)—specifically the use of Russian-operated proxy chains and the targeting of security researchers—show a high correlation with the GRU (Military Intelligence) and SVR (Foreign Intelligence Service).
- Targeting the "Watchers": The campaign specifically prioritized individuals within the spyware research and digital forensics community, suggesting a mission to monitor or neutralize those tracking Russian cyber-espionage tools.
- Operational Maturity: The synchronization between the social engineering phase and the technical execution of the account takeover (ATO) indicates a level of resource allocation and planning typical of state-sponsored APTs.
- Strategic Intelligence Goals: Beyond immediate surveillance, the objective appears to be the long-term compromise of "secure" channels used by high-value targets in the geopolitical and security sectors to maintain persistent access.
-
Infrastructure Analysis: Forensic Artifacts and Obfuscation
- Multi-Layered Proxy Chains: Attackers deployed a complex network of Russian-operated proxies and VPNs to obfuscate the geographic origin of the registration requests and evade automated rate-limiting triggers.
- Device Fingerprinting: Forensic sessions captured specific user-agent strings and device fingerprints, revealing the automated toolsets and operating environments used by the attackers to simulate legitimate Signal clients.
- SMS Intercept Logs: Recovered metadata from unauthorized sessions provided timestamped logs of SMS registration attempts, confirming the interception occurred at the carrier level rather than through device-side malware.
- C2 Infrastructure Overlap: The network infrastructure used to coordinate these attacks showed significant overlap with previously documented Russian espionage campaigns targeting encrypted communication apps.
-
Impact Analysis: The Encryption-Identity Paradox
- Erosion of the E2EE Assumption: This campaign proves that End-to-End Encryption (E2EE) is ineffective if the underlying identity layer—the account ownership itself—is compromised via telephony manipulation.
- Shift to Identity-Centric Attacks: The incident marks a critical trend where attackers bypass costly zero-day exploits in favor of exploiting less-secure authentication layers (SMS/PSTN) to achieve the same goal of account access.
- Regional Carrier Risk: The success of these hijacking attempts is directly tied to the security protocols of regional telecommunications providers, making users in jurisdictions with weak identity verification extremely vulnerable.
- Elevated Risk for High-Value Targets: There is a documented surge in activity targeting the global cybersecurity community, necessitating a fundamental reassessment of how security professionals verify their identity on "secure" platforms.
-
Defensive Roadmap: Strategic Mitigation and Hardening
- Mandatory Registration Lock: All high-risk users must enable Signal's "Registration Lock" feature, which requires a user-defined PIN to re-register an account, effectively neutralizing the threat of SIM swapping.
- Transition to Hardware-Based MFA: Organizations should move away from SMS-based authentication in favor of FIDO2/WebAuthn hardware security keys (e.g., YubiKey) to remove the telephony-based attack surface entirely.
- Enhanced Identity Monitoring: Security professionals should implement protocols to monitor for unusual registration patterns and unauthorized changes in device-binding metadata across all primary communication tools.
- Platform-Researcher Collaboration: There is an urgent need for real-time intelligence loops between platform providers and the research community to harden registration protocols against state-level bypass techniques.
Related posts
- techcrunch.com — A spyware investigator exposed Russian government hackers trying to hijack Signal accounts
- feeds.feedburner.com — Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
- Cyberinsider
- English
- Truesec
- Securityaffairs
- Infosecurity-magazine
- Paubox
- Cyberscoop
- Ic3
- Malwarebytes
- techcrunch.com — Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover
- Mlq
- Bankinfosecurity
- Transittalent
- Latimes
- Cyberdaily
- Dysruptionhub
- Thenextweb
- Internazionale
- Securitymagazine
- Dataminr
- Jns
- techcrunch.com — Hackers are trying to steal Signal users’ backups in new wave of phishing attacks
- Malware News — Signal users targeted in backup-stealing phishing attacks
- gbhackers.com — Hackers Target Signal Users to Steal Backups in New Attack Wave
- Cybersecurity News — Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks
- Cybersecurity News — Famous Chollima Hackers Target PHP Developers Using Compromised Packagist Package
- Datamation
- Thehackernews
- wiz.io — Miasma: Supply Chain Attack Targeting RedHat npm Packages
- Q52
- thehackernews.com — Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
- SANS Internet Storm Center — New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)
- gbhackers.com — Foreign Spyware Found on Phones of Top Russian Officials
- Cybersecurity News — Russia Says Foreign Spyware Found on High-Ranking Officials’ Mobile Phones
- Meduza
- Caliber
- Youtube
- Techmeme
- Macspaunday
- Therecord
- Mallory
- Securityaffairs
- Ua
- thehackernews.com — Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
- Canada
- SC Media — China-linked actors using job sites to target government workers, Five Eyes warns
- Therecord
- Ctvnews
- Theguardian
- Ic3
- Timesofindia
- Aha
- Pressinsider
- Hackread
- Sofx
- SecurityWeek — LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers