Signal and WhatsApp accounts targeted in phishing campaign
ID: b947a666-2447-533e-9185-267f90e0f1ec
STIX ID: report--b947a666-2447-533e-9185-267f90e0f1ec
Feed Name: Malwarebytes Blog
**Dutch AIVD/MIVD warn of a Russian state‑backed campaign** that uses phishing and social‑engineering—requesting SMS verification codes or PINs and abusing Signal/WhatsApp "linked devices" (GhostPairing)—to take over or silently monitor high‑value accounts (senior officials, military personnel, civil servants, journalists). The advisory notes encryption of the apps is not broken, describes attack variants, and recommends mitigations: never share verification codes or PINs, ignore in‑app "support" messages, only use QR/link device‑linking from the app's device‑linking menu, regularly review linked devices and group memberships, enable registration locks/2FA, and use disappearing messages or designated secure systems for sensitive communications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
