Russians are posing as Signal support to launch phishing attacks
ID: 1dbad99f-0fe7-5aa9-a43a-6e73f4d3edaa
STIX ID: report--1dbad99f-0fe7-5aa9-a43a-6e73f4d3edaa
Feed Name: The Register (Security)
Threat Score
**Infosec In Brief:** A news roundup reports multiple active threats including Russian intelligence-affiliated phishing used to takeover Signal accounts, Iran-linked domains used for psyops and doxxing (and an Intune-based attack on Stryker), a ransomware-related data theft affecting ~670,000 people, LeakNet’s ClickFix social-engineering delivering an in-memory loader, an AWS Bedrock sandbox DNS leakage issue, and an operational-security Strava location leak.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
