logo

Russian state hackers spy on Ukrainian military through Signal app

ID: e33043c9-e809-50ef-9dad-f984d4b9b908

STIX ID: report--e33043c9-e809-50ef-9dad-f984d4b9b908

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-02-19

Date Updated: 2026-05-01

...
...

Google researchers warn that Russian state-backed actors are actively targeting Signal messenger accounts used by Ukrainian military, government officials, journalists, and activists. Attackers employ phishing and malicious QR codes to abuse Signal's linked-devices feature, link attacker-controlled devices to victims in real time, and deploy malware (e.g., Wavesign, Pinpoint, PowerShell scripts) to exfiltrate messages and location data; named actors include Sandworm, UNC4221, and Turla, with researchers warning of growing demand for these offensive capabilities and ongoing improvements to Signal's defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.