The US government has announced a $10 million reward for information leading to the identification or location of members of two Russian-linked cyber groups accused of targeting Signal and WhatsApp accounts belonging to government officials, journalists, and other high-profile individuals.
What Happened
A phishing campaign attributed to the UNC5792 and UNC4221 hacker groups has compromised thousands of individual accounts for commercial messaging applications. The attackers use social engineering techniques to trick victims into sharing verification codes, account PINs, and backup recovery keys, enabling them to access message histories, private and group chats, and in some cases, take over victims' accounts.
The FBI and CISA have warned that the groups' espionage campaigns have evolved, with attackers increasingly attempting to steal backup recovery keys for encrypted messaging applications. Compromised backup recovery keys can remain valid even if victims create new accounts using the same phone number, potentially allowing attackers to regain access in the future.
Background and Context
The UNC5792 and UNC4221 hacker groups are linked to Russia's intelligence and military services. The US government has offered rewards for information leading to the identification of members of these groups under the Rewards for Justice program, which targets foreign state actors carrying out cyberattacks against US critical infrastructure.
The phishing campaign targets individuals described as being of "high intelligence value," including current and former US and international government officials, military personnel, political figures, journalists, and officials in Ukraine. The March advisory said the broader campaign had already compromised thousands of accounts worldwide.
Why it Matters to the Industry
The phishing campaign highlights the importance of robust security measures for messaging applications, particularly those used by high-profile individuals. The attackers' use of social engineering techniques to trick victims into sharing sensitive information underscores the need for users to be vigilant and cautious when interacting with suspicious messages.
The fact that compromised backup recovery keys can remain valid even after a victim creates a new account using the same phone number is particularly concerning, as it allows attackers to regain access in the future. This emphasizes the importance of regularly generating new backup recovery keys and invalidating old ones for future downloads.
What Comes Next
The US government's announcement of a $10 million reward for information leading to the identification or location of members of the UNC5792 and UNC4221 hacker groups is a significant development in the ongoing efforts to combat cybercrime. The FBI and CISA have warned that the groups' espionage campaigns continue, and users are advised to remain vigilant and take steps to protect their accounts.
The phishing campaign serves as a reminder of the importance of robust security measures for messaging applications and the need for users to be cautious when interacting with suspicious messages. As the industry continues to evolve, it is essential that developers and operators prioritize security and implement measures to prevent such attacks in the future.
Key Facts
- The US government has announced a $10 million reward for information leading to the identification or location of members of two Russian-linked cyber groups accused of targeting Signal and WhatsApp accounts.
- The attackers use social engineering techniques to trick victims into sharing verification codes, account PINs, and backup recovery keys.
- Compromised backup recovery keys can remain valid even if victims create new accounts using the same phone number.
- The phishing campaign targets individuals described as being of "high intelligence value," including current and former US and international government officials, military personnel, political figures, journalists, and officials in Ukraine.
- The FBI and CISA have warned that the groups' espionage campaigns continue, and users are advised to remain vigilant and take steps to protect their accounts.