Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger
ID: c947c355-acd0-57a6-a14d-a6ccea39fa3f
STIX ID: report--c947c355-acd0-57a6-a14d-a6ccea39fa3f
Feed Name: Google Cloud Threat Intelligence
This report describes Russian-aligned threat actors (UNC5792 and APT44) abusing Signal's legitimate "linked devices" feature by delivering malicious QR codes and modified group-invite pages that link victims' accounts to actor-controlled devices. Observed in both remote phishing and close-access battlefield operations, this low-signature technique enables persistent, real-time eavesdropping on secure conversations and is difficult to detect through centralized defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
