logo

Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger

ID: c947c355-acd0-57a6-a14d-a6ccea39fa3f

STIX ID: report--c947c355-acd0-57a6-a14d-a6ccea39fa3f

Feed Name: Google Cloud Threat Intelligence

Threat Score
90/100

Date Published: 2025-02-19

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

This report describes Russian-aligned threat actors (UNC5792 and APT44) abusing Signal's legitimate "linked devices" feature by delivering malicious QR codes and modified group-invite pages that link victims' accounts to actor-controlled devices. Observed in both remote phishing and close-access battlefield operations, this low-signature technique enables persistent, real-time eavesdropping on secure conversations and is difficult to detect through centralized defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.