Help rescue animals from the front line — shop our Companion Collection 🐾

Shop Now
News Feed

Russian hackers target Signal accounts in growing espionage effort

• 3 min read
Russian hackers target Signal accounts in growing espionage effort
An image of a woman holding a cell phone in front of the Signal logo displayed on a computer screen, on April 29, 2024, in Edmonton, Canada. (Photo by Artur Widak/NurPhoto via Getty Images)

Google’s Threat Intelligence Group (GTIG) has identified a rise in Russian state-backed hacking attempts aimed at compromising Signal messenger accounts.

These attacks primarily target individuals of interest to Russia's intelligence services, including military personnel, government officials, journalists, and activists.

While these efforts are currently tied to Russia’s war in Ukraine, experts warn that similar tactics may soon be adopted by other threat actors worldwide. The broader concern extends beyond Signal, as Russian-aligned groups have also been observed targeting messaging platforms like WhatsApp and Telegram using comparable methods, according to the group's latest report published on Feb. 19.

Experts warn that these attacks signal a growing global trend in cyber espionage, where governments and hacking groups are increasingly seeking to infiltrate secure messaging apps.

The primary technique used in these attacks involves exploiting Signal’s "linked devices" feature, which allows users to connect additional devices to their accounts. Hackers have crafted malicious QR codes that, when scanned, link a victim’s Signal account to a hacker-controlled device.

This enables them to intercept messages in real-time without needing direct access to the victim’s phone. Phishing campaigns distributing these malicious QR codes have been disguised as legitimate Signal security alerts, group invitations, or even official device-pairing instructions from the Signal website. In some cases, hackers have embedded these QR codes within fake applications designed to mimic software used by the Ukrainian military.

Beyond remote phishing, Russian cyber operatives have also deployed this tactic in battlefield scenarios.

The group APT44—also known as Sandworm, a unit linked to Russia’s military intelligence agency (GRU)—has reportedly used the method on captured devices. Soldiers’ Signal accounts are being linked to Russian-controlled infrastructure, allowing continued surveillance of sensitive conversations. This approach is difficult to detect because Signal does not have a centralized system for flagging new linked devices, meaning a successful breach could remain unnoticed for an extended period.

Signal, in collaboration with Google, has since strengthened its security measures to counter these phishing attempts. The latest updates for both Android and iOS include enhanced protections designed to prevent unauthorized device linking. Users are urged to update their apps to the newest version and remain cautious of suspicious QR codes or unexpected device-linking requests.

Avatar
Olena Goncharova

Special Correspondent

Olena Goncharova is the Special Correspondent for the Kyiv Independent, where she has previously worked as a development manager and Canadian correspondent. She first joined the Kyiv Post, Ukraine's oldest English-language newspaper, as a staff writer in January 2012 and became the newspaper’s Canadian correspondent in June 2018. She is based in Edmonton, Alberta. Olena has a master’s degree in publishing and editing from the Institute of Journalism in Taras Shevchenko National University in Kyiv. Olena was a 2016 Alfred Friendly Press Partners fellow who worked for the Pittsburgh Post-Gazette for six months. The program is administered by the University of Missouri School of Journalism in Columbia.

Read more
News Feed

The latest announcement comes as Kyiv experienced widespread power outages on Oct. 8 following a Russian attack on Ukrainian energy infrastructure. Over 3 million residents in the capital lost power in what officials described as "an attack on one of the energy facilities important for the city of Kyiv."

The railway operator initially reported that the passenger train's driver suffered a leg injury and four passengers required medical attention. The crew of the electric locomotive was unharmed.

 (Updated:  )

"The government looks forward to the smooth resolution of all pending issues between the two countries and will continue consultations with the Ukrainian side to this end," the South Korean Foreign Ministry said in a press release.

Show More