Russian spies are now tricking Signal users into handing over a key to restore their backup, FBI says


TL;DR

The FBI warns that Russian hackers are phishing for backup recovery keys that give signal users permanent access to their message history.

The FBI and CISA have warned about this Russian intelligence hackers are now targeting Signal users’ backup restore keys. the expansion of a phishing campaign that stole thousands of accounts around the world. The updated advisory, published Thursday, says that a single handover of the key allows attackers to restore an account’s backup, read its entire private and group message history, and hijack the account.

The switch continues to work even after the victim switches phones. The advisory warns that if the target creates a new account on the same phone number, the old recovery key can still be used to access future backups. The only solution is to generate a new key in the Alarm settings, which invalidates the old one for future downloads, but cannot recover anything the attacker has already downloaded.

The advisory, designated PSA I-062626-PSA, adds two public trace names not included in the FBI’s March notice: UNC5792 and UNC4221. The bureau coordinates this activity with multiple groups of Russian Intelligence Services, including FSB officers embedded in the FSB Border Guard and others working in the Russian military. The campaign targets both Signal and WhatsApp, although the recovery key tactic is specific to Signal.

💜 of EU technology

The latest rumblings from the EU tech scene, a story from our wise founder Boris and some questionable AI art. Free in your inbox every week. Register now!

The targets are those described by the FBI.high intelligence value,” including current and former US and international government officials, military personnel, politicians, journalists and officials in Ukraine.The March advisory said the broader campaign has already compromised thousands of accounts around the world.

Phishing messages act as Signal support. Previous waves required or “doctored” SMS verification codes and account PINs.group invitation” links that silently lock the attacker’s device to the victim’s account.The updated version fools targets by turning on Signal backups, opening a recovery button screen, and pasting the key into a conversation.

The FBI released two sample messages used in the campaign. One is masquerading as mandatory two-factor authentication, and the other is an emergency “data recovery” fix for messages believed to be at risk of being lost.Both social engineering attacks which exploits trust in the platform’s own interface rather than technical vulnerabilities.

The agencies are clear that none of these methods break Signal’s encryption or the app itself. Attackers compromise individual accounts through social engineering, then log in through a legitimate feature. This is an example increasingly common among security productswhere the weakest link is the person holding the device, not the cryptography that protects the information.

In addition to the tip, the State Department’s Rewards for Justice program is offering up to $10 million for information about UNC5792. The action coincides with earlier warnings from the Dutch intelligence agencies AIVD and MIVD, Germany’s BfV and BSI and France’s ANSSI. Google’s Threat Intelligence Group first documented UNC5792 exploiting Signal’s connected device feature in early 2025, and later observed the same commercial tool targeting WhatsApp and Telegram.

The campaign is a reminder that end-to-end encryption protects messages in transit, but cannot protect users who are persuaded to hand over the keys themselves. Anyone who receives a message requesting a recovery key, verification code, or PIN within Signal should treat it as a hostile, no matter how convincing the sender appears. Signal does not send in-app messages to users to request credentials.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *