Multiple Russia-aligned threat actors are targeting Signal Messenger, using phishing campaigns to compromise accounts and steal sensitive information. The attackers abuse Signal's 'linked devices' feature, crafting malicious QR codes that link a victim's account to an actor-controlled Signal instance. This allows them to eavesdrop on secure conversations in real-time. The threat actors have also been observed using malware to steal Signal database files from Android and Windows devices.