
Federal law enforcement has announced a reward program seeking information on two Russian state-affiliated cyber groups responsible for a sustained phishing campaign targeting encrypted messaging applications. The operation, attributed to clusters designated UNC5792 and UNC4221, has been active since at least March and has resulted in the compromise of thousands of accounts belonging to high-value targets including current and former US government officials, military personnel, political figures, and investigative journalists.
The attackers employ social engineering tactics that masquerade as legitimate support communications from Signal or WhatsApp. Initial waves of the campaign direct recipients to click links or provide verification codes, potentially linking an attacker’s device to the victim’s account or enabling complete account takeover. A more recent evolution of the operation instructs users to create backups of their communications and provide encryption passcodes, which grants attackers access to previously encrypted conversations. While Signal’s architecture prevents attackers from accessing historical messages in typical account compromises, the backup extraction method circumvents this protection.
The deceptive messages are crafted to appear authentic, referencing legitimate platform features and claiming urgent security concerns. Some variants exploit Signal’s group invitation functionality by redirecting users to malicious URLs. The phishing approach, while relatively unsophisticated from a technical standpoint, has proven effective because targets may be fatigued, distracted, or otherwise momentarily inattentive to security protocols.
On Monday, the US State Department announced the reward offer through its Reward for Justice program, seeking information on the identities or locations of individuals involved in the campaign. UNC5792 is associated with the Russian Federal Security Service’s Border Guards division, while UNC4221 operates on behalf of Russian military services. Users who have already disclosed backup recovery keys are advised to generate new ones, though this action does not prevent attackers from accessing previously downloaded backup data.