Russian hackers target military, officials with whatsapp, signal account breach

Intelligence agencies have issued a global alert after a sophisticated cyberattack targeting military personnel, government officials, and journalists. The attacks, linked to the Russian government, exploit phishing and social engineering to compromise WhatsApp and Signal accounts.

Dutch agencies warn of coordinated campaign

Dutch agencies warn of coordinated campaign

The Dutch National Cyber Security Centre (MIVD) and the General Security Service (AIVD) jointly revealed a coordinated global campaign aimed at individuals of interest to the Russian government, including employees of the Dutch government. The report details how Russian state-sponsored hackers employ social engineering tactics, primarily phishing, to gain access, control, or link victim accounts and devices.

The methods are insidious: malicious links and fraudulent QR codes lure users to compromised groups or prompt login on alternative devices. Once a user’s account is breached, the attackers gain access to contact lists and read conversations, including those within group chats – effectively exposing a wealth of shared information.

One particularly concerning technique involves impersonating the messaging apps' technical support chatbots. Signal users, for instance, have been targeted by fake support messages claiming suspicious activity, urging them to share verification codes and PINs to prevent data leaks. The compromised code, sent to the attacker by SMS, combined with the PIN, grants complete control over the account, even allowing the attacker to redirect verification codes to a different number.

Security authorities are urging users to exercise extreme caution. The advice includes avoiding sending sensitive information through instant messaging apps, regularly checking login devices, ignoring chatbot verification prompts, and never sharing SMS-delivered codes. Users are also warned against scanning unverified QR codes and activating disappearing messages to avoid a digital trail.

Signal has acknowledged the attacks on its Bluesky account, reinforcing best practices. They emphasize that SMS verification codes are only needed during initial registration, and actively warn users against sharing them. The company is also implementing enhanced security measures to mitigate the risk.

The speed and precision of these attacks underscore the growing sophistication of state-sponsored cyber operations. The incident serves as a stark reminder of the pervasive threat landscape and the importance of robust cybersecurity practices, a lesson many are only beginning to fully grasp.