HackMyIP
← Back to News
2026-06-27 The Hacker News

Russian Hackers Use Fake Signal Support Texts to Steal Messaging Credentials

PhishingAPTAuthentication

Ukraine's Security Service (SSU), working alongside the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage campaign attributed to Russian intelligence services targeting messaging accounts belonging to government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The operation, designed to exfiltrate sensitive military, political, and economic communications as well as personal data, leverages SMS messages impersonating legitimate messaging platform support bots to trick high-value targets into surrendering their account credentials. Similar attack waves against Signal and WhatsApp users have previously been linked to Russian threat clusters tracked as Star Blizzard, UNC5792 (UAC-0195), and UNC4221 (UAC-0185).

According to the SSU, the campaign extends beyond organizational and public figures to include personal accounts of ordinary Ukrainian nationals, signaling a broad-scope intelligence collection effort. The disclosure follows the FBI's recent attribution of Russian Intelligence Services (RIS) actors to an ongoing commercial messaging application (CMA) phishing operation aimed at deceiving targets into handing over backup recovery keys. CERT-UA has also tied Belarus-aligned threat actor UNC1151 (Ghostwriter / UAC-0057) to a spear-phishing campaign using compromised accounts to deliver the OYSTERBLUES information stealer against Ukrainian government organizations.

Defenders and end users are urged to periodically review active messaging sessions, log out of unknown connections, enable two-factor authentication, and avoid scanning QR codes or sharing confirmation codes, PINs, passwords, or account recovery keys from unverified sources. Anyone concerned about exposed credentials can verify their accounts with the email breach checker, while users should also evaluate their authentication hygiene using the password checker. A broader review of digital exposure through the privacy checkup can help identify lingering risks across messaging and identity surfaces.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →