Russian state hackers spy on Ukrainian military through Signal app
ID: e33043c9-e809-50ef-9dad-f984d4b9b908
STIX ID: report--e33043c9-e809-50ef-9dad-f984d4b9b908
Feed Name: The Record from Recorded Future News
Google researchers warn that Russian state-backed actors are actively targeting Signal messenger accounts used by Ukrainian military, government officials, journalists, and activists. Attackers employ phishing and malicious QR codes to abuse Signal's linked-devices feature, link attacker-controlled devices to victims in real time, and deploy malware (e.g., Wavesign, Pinpoint, PowerShell scripts) to exfiltrate messages and location data; named actors include Sandworm, UNC4221, and Turla, with researchers warning of growing demand for these offensive capabilities and ongoing improvements to Signal's defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
