Russian Intelligence Steals Messaging Credentials via Fake Support Texts

A joint SSU-FBI investigation reveals a Russian intelligence phishing campaign targeting messaging accounts of officials and civilians.

By Central
The campaign uses fake support texts to steal Signal and WhatsApp credentials from Ukrainian, European, and US targets.
Highlights
  • Russian intelligence services are behind a phishing campaign targeting messaging accounts of government and military personnel.
  • The attack relies on fake SMS messages impersonating official support bots to harvest credentials.
  • The campaign is linked to threat groups like Star Blizzard and UNC5792, with coordination across multiple state-aligned actors.

The Security Service of Ukraine (SSU), working jointly with the U.S. Federal Bureau of Investigation (FBI), has exposed a sustained cyber espionage campaign orchestrated by Russian intelligence services designed to compromise the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The operation, which has been active for an extended period, aims to siphon sensitive military, political, and economic communications from targeted individuals, as well as harvest personal data for further exploitation.

How the Attack Works: Fake Support Texts Targeting Messaging Accounts

The attack chain relies on a straightforward but effective social engineering technique. Victims receive SMS messages that impersonate the official support bot of a popular messaging platform. These fraudulent messages urge recipients to disclose their account credentials, often by following a link or replying with sensitive information such as confirmation codes, PINs, passwords, or account recovery keys. The SSU stated that the campaign is not limited to high-profile targets but also extends to personal accounts belonging to ordinary Ukrainian nationals, significantly broadening the pool of potential victims.

Threat Actors Behind the Campaign

While the SSU did not attribute the operation to a specific hacking group, similar phishing waves targeting Signal and WhatsApp users have been linked by cybersecurity researchers to known Russian threat activity clusters. These include Star Blizzard, UNC5792 (also tracked as UAC-0195), and UNC4221 (also known as UAC-0185). The FBI has separately attributed an ongoing commercial messaging application (CMA) phishing campaign to Russian Intelligence Services (RIS) cyber threat actors, noting that high-value targets are deceived into handing over their backup recovery keys, which can then be used to gain full access to encrypted message histories.

Broader Context: Coordinated Phishing Across Multiple Threat Groups

The disclosure follows a related warning from the Computer Emergency Response Team of Ukraine (CERT-UA), which late last month attributed a spear-phishing campaign to the Belarus-aligned threat actor UNC1151 (also known as Ghostwriter and UAC-0057). That operation used compromised accounts to target government organizations and deliver an information-stealing malware called OYSTERBLUES. Taken together, these incidents underscore a coordinated and persistent effort by state-aligned actors to compromise messaging infrastructure used by military, governmental, and civil society targets in Ukraine and allied nations.

What Affected Users Should Do Now

Individuals who suspect their messaging accounts may have been targeted should take immediate defensive steps. First, review all active sessions for your messaging apps and log out of any unknown or unrecognized connections. Enable two-factor authentication on every account that supports it, using an authenticator app rather than SMS-based codes when possible. Never disclose confirmation codes, PINs, passwords, or account recovery keys to anyone who contacts you unsolicited, regardless of how official the message appears. Avoid scanning QR codes received from unknown users, and refrain from clicking suspicious links or opening files from unfamiliar or dubious chats. For those seeking additional protection, consider using a reputable VPN with a verified no-logs policy and AES-256 encryption when accessing messaging services over public Wi-Fi networks, as this adds a critical layer of encryption that can help thwart credential harvesting attempts. Finally, periodically review and rotate your account recovery keys and backup codes, storing them securely offline rather than in cloud storage or email.

Share This Article