Russian APT Groups Target EU Officials via Signal and WhatsApp Phishing
Nation-state hackers linked to Russian intelligence services have shifted their operational focus from traditional email-based phishing to encrypted messaging platforms, targeting European Union officials on Signal and WhatsApp. According to reporting by Dark Reading, multiple EU member states have observed coordinated spear-phishing campaigns designed to harvest credentials and deploy malware through these messaging channels, exploiting the very apps governments have adopted for sensitive internal communications.
The campaigns are consistent with tactics attributed to Russian advanced persistent threat (APT) groups such as APT29 (Cozy Bear) and GRU-affiliated units, which have historically relied on credential phishing, OAuth abuse, and malicious attachments. Attackers are reportedly impersonating diplomatic contacts and EU institutional figures, sending messages containing links to lookalike login portals for Signal, WhatsApp Web, and Microsoft 365. Once credentials are entered, adversaries can intercept 2FA codes, hijack accounts, and pivot into broader government networks. Officials can verify whether their email addresses have been exposed in known incidents using a breach lookup tool to determine if compromised credentials may already be circulating on dark web marketplaces.
The pivot to messaging platforms complicates detection for security teams, as traffic from Signal and WhatsApp is end-to-end encrypted and resides outside standard email security gateways. EU governments are now reassessing their reliance on consumer messaging apps for official business, with several agencies issuing interim guidance that mandates out-of-band verification for any sensitive requests received via these channels. Personnel are being instructed to confirm message authenticity through a secondary channel before acting on instructions involving financial transfers, credential resets, or document sharing.
Defenders are urged to audit account exposure and harden authentication. Security teams can run a quick password strength audit on accounts tied to official communications and enroll hardware security keys where supported, since SIM-swap and phishing-as-a-service kits targeting SMS-based 2FA remain prevalent. A broader privacy and exposure checkup can also help officials identify leaked metadata, browser artifacts, and misconfigured devices that adversaries may leverage to profile high-value targets within diplomatic and policy-making circles.