Russian Hackers Target Signal and WhatsApp Accounts in Global Espionage Campaign
Russian state-sponsored hackers are conducting a large-scale cyber espionage campaign targeting Signal and WhatsApp accounts used by dignitaries, military personnel, civil servants, and journalists, according to intelligence agencies in the Netherlands. The campaign relies on social engineering tactics rather than exploiting software vulnerabilities, highlighting the ongoing risk of account compromise even with complete-to-end encryption.
Campaign Details and Tactics
The Dutch General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD) have warned that the hackers are employing several methods to gain access to accounts. These include:
- Spoofing Signal Support: Hackers impersonate Signal support staff in chats to trick victims into sharing security verification codes or Signal PINs.
- Exploiting Linked Devices: Attackers persuade victims to scan QR codes or click malicious links that connect the hacker’s device to the victim’s account. This allows the hackers to read conversations without alerting the account owner. TechRadar reports this method allows spies to read conversations without the victim’s knowledge.
- WhatsApp “Connected Devices” Function: Hackers are leveraging the “Connected Devices” feature on WhatsApp to gain access to chat groups.
According to the TechRepublic, the campaign is global in scope and has already likely yielded sensitive information.
Why Social Engineering is Effective
This campaign demonstrates that even secure messaging apps are vulnerable when attackers focus on the user rather than the application itself. End-to-end encryption protects messages in transit, but it cannot prevent account takeover if an attacker obtains the necessary credentials or gains access through linked devices. As TechRepublic points out, strong privacy features are ineffective once an attacker controls the account.
Previous Russian Cyber Activity
The Netherlands has a history of identifying and disrupting Russian cyber operations. Dutch intelligence agencies previously thwarted a Russian military intelligence (GRU) espionage attempt targeting the Organization for the Prohibition of Chemical Weapons (OPCW) in The Hague and uncovered a GRU attempt to infiltrate an agent at the International Criminal Court. This experience lends credibility to their assessment of the current campaign.
What Users Can Do
To protect against these attacks, users should:
- Be wary of unsolicited messages: Do not trust messages from unknown contacts or those requesting sensitive information.
- Never share verification codes or PINs: Legitimate support services will never ask for these codes.
- Exercise caution with QR codes and links: Only scan QR codes or click links from trusted sources.
- Review linked devices: Regularly check the list of linked devices in your Signal and WhatsApp settings and remove any unfamiliar devices.
Looking Ahead
The ongoing campaign highlights the evolving tactics of state-sponsored hackers and the importance of user vigilance. As Cybernews reports, this is a global issue impacting officials, military personnel, and journalists. Continued awareness and proactive security measures are crucial to mitigating the risk of account compromise and protecting sensitive information.
Related reading