Russian Hackers Evolve Tactics to Steal Signal Backup Recovery Keys
The FBI and CISA have issued an updated public service announcement warning that a phishing campaign attributed to Russian intelligence services has evolved to target Signal users' backup recovery keys. This allows attackers to access victims' historical messages, including private and group conversations.
The campaign, publicly tracked as UNC5792 and UNC4221, targets individuals of high intelligence value, including current and former US and international government officials, military personnel, political figures, journalists, and key officials located in Ukraine. The threat actors are believed to be officers embedded with Russia's Federal Security Service (FSB) Border Guards and other actors working on behalf of the Russian military.
New Phishing Tactic Targets Signal Backups
The updated alert warns that the attackers have changed their tactics from attempting to steal verification codes or account PINs to targeting Signal backup recovery keys. The threat actors impersonate Signal support teams, sending phishing messages that falsely claim Signal is introducing mandatory two-factor verification following an alleged wave of attacks by hackers from Iran and post-Soviet countries.
The phishing messages prompt users to set up their Signal backup, which stores encrypted copies of conversations on Signal's cloud servers. The data is end-to-end encrypted using the recovery key, which should never be given to anyone else. However, once the attackers obtain the recovery key, they can restore the backup to their own devices and gain access to the victim's historical messages.
Recovery Scenario Warning
The updated advisory also warns of a recovery scenario that users may miss after their account was compromised. If an attacker obtains a user's backup recovery key, creating a new Signal account using the same phone number does not invalidate the old stolen key. Instead, users must generate a new backup recovery key through Signal's backup settings, which invalidates the previous key for future backup downloads.
However, generating a new recovery key will not prevent attackers from accessing backups they already downloaded using the compromised key. The agencies remind users that legitimate messaging application support teams only communicate through official company email addresses, never request verification codes within the application, and do not send links asking users to verify or restore their accounts.
Reporting Incidents
Anyone who believes they have fallen victim to the campaign is encouraged to report the incident to the FBI's Internet Crime Complaint Center (IC3), a local FBI field office, or CISA. It is essential for users to be cautious when receiving phishing messages and to never give out their backup recovery keys or other sensitive information.
- Report incidents to the FBI's Internet Crime Complaint Center (IC3)
- Contact a local FBI field office
- Reach out to CISA
By being aware of these phishing tactics and taking the necessary precautions, Signal users can protect their accounts and prevent unauthorized access to their historical messages.
Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper to learn more about protecting your organization from cyber threats.
Source: BleepingComputer