Russian threat actors have been launching phishing campaigns that exploit the legitimate “Linked Devices” feature in the Signal messaging app to gain unauthorized access to accounts of interest. Over the past year, researchers observed phishing operations attributed to Russian state-aligned groups that used multiple methods to trick targets into linking their Signal account to a device controlled by the attacker. In a report today, Google Threat Intelligence Group (GTIG) says that abusing Signal’s device linking feature is the “most novel and widely used technique underpinning Russian-aligned attempts to compromise Signal accounts.” Threat actors leveraged the feature by creating malicious QR codes and deceiving potential victims into scanning them to allow Signal messages to synchronize with the attacker’s device. It is a simple trick that does not require a full compromise of the target’s device to monitor their secure conversations. GTIG researchers observed this method being adapted by the type of target. In a broader campaign, the attacker would disguise the malicious code as a legitimate app resource (e.g. Signal group invites) or as device pairing instructions from the legitimate Signal website. For targeted attacks, the threat actor would add the malicious QR codes to phishing pages designed to be of interest to the potential victim, such as “specialized applications used by the ultimate targets of the operation.” Additionally, GTIG noticed that the infamous Russian ...
Russian phishing campaigns exploit Signal's device-linking feature
BleepingComputer
·Ionut Ilascu
·Published Feb 19, 2025
·Updated
Affected Software
2 affected components
Signal Signal
Signal Signal
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Russian phishing campaigns exploiting the Linked Devices feature in the Signal messaging app.
2
What security implications are discussed?
The security implications involve unauthorized access to user accounts, potentially leading to data breaches.
3
What products or software are affected?
The affected software is the Signal messaging app.
4
How do the phishing campaigns exploit Signal's features?
The phishing campaigns utilize the legitimate Linked Devices feature to trick users into granting access.
5
What have researchers observed regarding these phishing campaigns?
Researchers have observed a rise in these phishing campaigns over the past year targeting Signal users.