logo

Russians are posing as Signal support to launch phishing attacks

ID: 1dbad99f-0fe7-5aa9-a43a-6e73f4d3edaa

STIX ID: report--1dbad99f-0fe7-5aa9-a43a-6e73f4d3edaa

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-03-22

Date Updated: 2026-04-26

Author: Matt Rosoff

...
...

**Infosec In Brief:** A news roundup reports multiple active threats including Russian intelligence-affiliated phishing used to takeover Signal accounts, Iran-linked domains used for psyops and doxxing (and an Intune-based attack on Stryker), a ransomware-related data theft affecting ~670,000 people, LeakNet’s ClickFix social-engineering delivering an in-memory loader, an AWS Bedrock sandbox DNS leakage issue, and an operational-security Strava location leak.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.