Cyber Attacks

Russian Hackers target Signal and WhatsApp accounts

0

Russian-linked hackers are carrying out a global campaign to compromise Signal and WhatsApp accounts belonging to government officials, military personnel, and civil servants, according to a warning from Dutch intelligence agencies.

The Netherlands’ intelligence services, MIVD and AIVD, say the operation focuses on individuals involved in government, defense, and national security. Officials confirmed that Dutch government employees have already been targeted, and other individuals of interest to Russia—including journalists—could also be at risk.

Attackers are not exploiting vulnerabilities in the messaging apps themselves. Instead, they use social engineering techniques to trick users into revealing verification codes or to link their accounts to attacker-controlled devices. In some cases, hackers impersonate Signal Support or abuse the “linked devices” feature to gain access to victims’ messages and group chats.

Dutch intelligence noted that Russia is particularly interested in Signal because of its strong end-to-end encryption, which makes it widely used for sensitive communication. Authorities emphasized that messaging apps like Signal and WhatsApp should not be used to share classified or confidential information.

Security experts say the attackers typically target individual accounts rather than the platforms themselves. Once access is obtained, hackers can monitor conversations, read messages, and gather intelligence from chat groups that may include government or military discussions.

To reduce the risk, Dutch agencies advise users to monitor group chats for suspicious activity, such as duplicate contacts with similar names or unfamiliar members joining conversations. Any unusual behavior should be reported to organizational security teams and verified through alternative channels like phone or email. Group administrators are also encouraged to remove unauthorized accounts and recreate chat groups if compromise is suspected.

The warning follows earlier research from the Google Threat Intelligence Group (GTIG), which reported that several Russia-linked threat actors were targeting Signal accounts used by individuals of interest to Russian intelligence. Researchers said these tactics are likely to expand beyond Ukraine and continue globally.

One notable method involves malicious QR codes designed to exploit Signal’s device-linking feature. When victims scan these codes—often disguised as group invitations, security alerts, or pairing instructions—their accounts become linked to attacker-controlled devices. This allows hackers to receive messages in real time without needing full access to the victim’s device.

Some campaigns have embedded these QR codes in phishing pages designed to mimic legitimate applications used by the Ukrainian military. Other attacks have modified Signal group invitations to trick users into linking their accounts.

Threat actors associated with groups such as APT44 (Sandworm) and UNC5792 have also been linked to these operations. In certain cases, attackers reportedly stole Signal database files from Android and Windows systems using malware, scripts, and command-line tools to exfiltrate data.

Dutch intelligence has released a cyber advisory outlining how users can identify potential compromises and respond to attacks, urging organizations to remain vigilant as the campaign continues.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Chrome flaw enabled Gemini Panel Privilege Escalation

Previous article

Starbucks data breach exposes data of 889 employees

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *