news.volyx.in

Multiple Russia-aligned threat actors actively targeting Signal Messenger (cloud.google.com)

836 points by karel-3d · 530 days ago · 289 comments on HN

Article summary

Multiple Russia-aligned threat actors are targeting Signal Messenger, using phishing campaigns to compromise accounts and steal sensitive information. The attackers abuse Signal's 'linked devices' feature, crafting malicious QR codes that link a victim's account to an actor-controlled Signal instance. This allows them to eavesdrop on secure conversations in real-time. The threat actors have also been observed using malware to steal Signal database files from Android and Windows devices.

Main themes

  • Signal Messenger security
  • Russia-aligned threat actors
  • Phishing campaigns
  • Secure communication
  • Cyber warfare
  • Mobile device security

What commenters say

  • The best way to protect against these phishing attacks is to be cautious when scanning QR codes and to regularly check for unexpected linked devices in the Signal settings menu.
  • Signal should consider exposing linked devices directly in the UI at all times to increase transparency and security.
  • The use of smartphones on the battlefield poses significant security risks, including the potential for sensitive information to be compromised if a device is captured or hacked.
  • The Russian military's tactics, including the use of 'meat wave' attacks, have been ineffective and have resulted in significant losses, contrary to some claims.
  • The security of smartphones on the battlefield is not a significant concern, as standard counter-measures such as encryption and passcode locks are sufficient to protect against most threats.
  • The use of encrypted digital radios is standard in modern military operations, and the lack of such technology has hindered the Russian military's efforts.
  • The article highlights the importance of securing smartphones on the battlefield, as they can store sensitive data and be used to call in artillery strikes or other military operations.
  • The new feature to sync old messages on Signal may potentially make the phishing attack vector worse, especially if the toggle is on by default and users are not careful when linking new devices.