
The FBI has issued a warning that Russian-backed hackers are targeting users of encrypted messaging apps like Signal and WhatsApp through phishing attacks. These attacks have already compromised thousands of accounts.
This FBI announcement is the first to directly link these attacks to Russian intelligence, rather than just generally labeling them as state-sponsored.
According to the FBI, the attacks are designed to get around the security of end-to-end encryption in messaging apps, not by breaking the encryption itself, but by taking over accounts.
The FBI notes that the techniques used can be applied to various messaging apps but are mainly aimed at Signal users.
With access to an account, the attackers can read private messages, view contact lists, pretend to be the account owner, and start new phishing campaigns using the victim’s trusted contacts.
The FBI reports that “thousands” of accounts globally have been affected, mainly those belonging to people with access to private data.
The FBI’s warning states that “The activity targets individuals of high intelligence value, such as current and former U.S. government officials, military personnel, political figures, and journalists.”
The FBI warning comes after similar announcements from Dutch and French cybersecurity agencies about similar account hijacking efforts.
Earlier in the month, Dutch intelligence agencies warned that government-backed attackers were using phishing to access Signal and WhatsApp accounts, with the goal of intercepting secure communications.
The Dutch advisory highlighted that the attacks involved tricking users into allowing attackers to add accounts to their devices or connect attacker-controlled devices to the accounts.
Now, France’s Cyber Crisis Coordination Center (C4) has also issued an alert about these tactics targeting instant messaging apps stating that the malicious activity is widespread and still in progress across multiple nations.
All mentioned advisories state that the phishing attacks use the same method of accessing accounts either by taking over the account or linking a device to the account, thereby avoiding the platform’s encryption.
The FBI explains that most phishing messages mimic support accounts and ask the targets to do something that will give the hackers access to their accounts secretly.
Targets are often tricked into sending verification codes or scanning QR codes that connect their accounts to devices under hacker control.
Once the hackers get access to accounts, they can secretly watch communications, join group chats, and send messages pretending to be the real user. This makes it harder to spot the attack and allows them to conduct additional phishing schemes.
The PSA makes it clear that the encryption of Signal, WhatsApp, and similar apps is not being broken, and no vulnerabilities are being used.
The FBI states the campaign has granted attackers unauthorized access to thousands of messaging accounts, subsequently used to target more victims.
Users are encouraged to be suspicious of unexpected messages, careful about scanning QR codes or linking devices to their accounts, and to never share verification codes with anyone, including accounts claiming to be platform support.
#behind #fbi #news #phishing #russian #says #signal #spies #the — News
© Bulletproof Servers. All rights reserved.