A spyware investigator exposed Russian government hackers trying to hijack Signal accounts

TL;DR

A cybersecurity researcher exposed a Russian hacking campaign targeting Signal users, including high-profile figures. The hackers used phishing tactics and automated tools to compromise accounts, with ongoing attacks confirmed. The investigation highlights the threat posed by state-backed cyber espionage.

A cybersecurity researcher has revealed a targeted hacking campaign by Russian government-backed hackers attempting to hijack Signal messaging accounts, affecting more than 13,500 users including politicians and journalists.

Donacha Ó Cearbhaill, a security researcher at Amnesty International’s Security Lab, discovered that the hackers used a tool called ApocalypseZ to automate their attack efforts, targeting large numbers of Signal users in bulk. The hackers impersonated Signal support, sent phishing messages, and attempted to trick users into revealing verification codes, which would allow them to gain control of accounts.

Ó Cearbhaill identified that the attack infrastructure was operated in Russian, with the codebase and interface language in Russian, and observed that the hackers were translating victim chats into Russian. He linked this campaign to broader efforts by Russian state-backed actors, as confirmed by multiple Western cybersecurity agencies, including CISA and UK cybersecurity officials, who have warned of similar campaigns.

Why It Matters

This development underscores the ongoing threat of state-sponsored cyber espionage targeting secure messaging platforms. The campaign’s scale, involving thousands of targets, including high-profile individuals, highlights the vulnerabilities in encrypted communication tools and the persistent efforts by nation-states to compromise political, journalistic, and diplomatic figures. It raises concerns about the security of personal and professional communications and the potential for espionage and misinformation.

Thetis Pro-C FIDO2 (L2) Security Key Passkey Device with USB C & NFC, TOTP/HOTP Authenticator APP, FIDO 2.0 Two Factor Authentication 2FA MFA, Supports Windows/macOS/Linux/Gmail/Facebook/Dropbox

Thetis Pro-C FIDO2 (L2) Security Key Passkey Device with USB C & NFC, TOTP/HOTP Authenticator APP, FIDO 2.0 Two Factor Authentication 2FA MFA, Supports Windows/macOS/Linux/Gmail/Facebook/Dropbox

FIDO2 Level 2 Passkey Authentication: Enable secure, passwordless sign-in on supported services using a certified FIDO2 Level 2…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

Earlier this year, security researchers and intelligence agencies identified Russian hackers attempting to infiltrate various communication platforms, including Signal. The campaign, which has been linked to Russian state-backed groups, uses automated tools to identify and target potential victims, especially those with high-profile or sensitive roles. Signal has issued warnings to its users about phishing attempts, and authorities have increased awareness of the threat landscape surrounding encrypted messaging apps.

“Having the attack land in my inbox, and the chance to turn the tables on the attackers and understand more about the campaign was too good to pass up.”

— Donncha Ó Cearbhaill

“I am convinced this was the same Russian government hacking group behind similar campaigns.”

— Ó Cearbhaill

“The campaign aligns with previous activity attributed to Russian government actors targeting encrypted communication platforms.”

— Cybersecurity agencies (CISA, UK NCSC)

McAfee Total Protection with Scam Detector | Avoid Phishing Emails, Texts, Video and QR Code Scams with Scam Protection Software App for iPhone & Android | 1-Year Subscription with Auto-Renewal

McAfee Total Protection with Scam Detector | Avoid Phishing Emails, Texts, Video and QR Code Scams with Scam Protection Software App for iPhone & Android | 1-Year Subscription with Auto-Renewal

ALL-IN-ONE SCAM PROTECTION – Stop sophisticated phishing attacks before they reach you; our scam detection helps you avoid…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

While the campaign’s infrastructure and methods have been identified, the full scope of targets remains unclear, and it is not confirmed whether the hackers have succeeded in gaining long-term access to any accounts. The extent of the campaign’s impact on high-profile individuals and government officials is still being assessed, and the hackers’ ultimate objectives are not fully known.

ECT Encrypted Calls & Text Mobile Security Solution

ECT Encrypted Calls & Text Mobile Security Solution

No cell provider is needed! Use current or old Android cell phones. No charges / fees / contracts…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

Authorities and Signal are expected to enhance security measures and issue further warnings. Monitoring of ongoing attacks continues, and investigations are likely to identify additional victims and infrastructure. Signal users are advised to enable security features such as Registration Lock to protect their accounts.

Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts

Yubico – YubiKey 5 NFC – Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified – Protect Your Online Accounts

POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How are the hackers attempting to hijack Signal accounts?

The hackers use phishing messages impersonating Signal support, tricking users into revealing verification codes, and deploying automated tools to target large groups of users.

Who is believed to be behind these attacks?

Multiple cybersecurity agencies attribute the campaign to Russian government-backed hacking groups, based on technical indicators and language used in the infrastructure.

What can Signal users do to protect themselves?

Users are advised to enable the Registration Lock feature, which requires a PIN to register the account on new devices, and to remain vigilant against phishing attempts.

Are high-profile targets involved?

Yes, reports indicate that politicians, journalists, and other prominent figures have been targeted, though the full scope of affected individuals is still being investigated.

You May Also Like

Show HN: Semble – Code search for agents that uses 98% fewer tokens than grep

Semble, a new code search library for agents, reduces token usage by 98% compared to grep+read, boosting speed and efficiency without external dependencies.

Mado: Fast Markdown linter written in Rust

Mado, a new markdown linter written in Rust, offers significantly faster performance than existing tools, supporting CommonMark and GFM syntax.

iPhone 18 Pro Max vs Google Pixel 11 Pro XL: Main differences to expect

Compare the upcoming iPhone 18 Pro Max and Google Pixel 11 Pro XL, focusing on design, display, performance, and camera features based on current rumors and leaks.

Where OpenClaw Security Is Heading

OpenClaw outlines ongoing efforts to improve security, including filesystem safety, network controls, and plugin trust, amid rapid development.