Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
The Security Service of Ukraine (SSU), working in partnership with the U.S. Federal Bureau of Investigation (FBI), announced it has uncovered a prolonged campaign run by Russian intelligence aimed at compromising user accounts on popular messaging platforms.
According to the SSU, the operation targeted a wide range of high-value and private individuals - including government officials, members of the armed forces, politicians and activists - across Ukraine, other European countries and the United States. The agency described the activity as a systematic effort to exfiltrate sensitive information from victims.
In a post published to Telegram, the SSU warned that attackers were attempting to obtain access to confidential military, political and economic communications, in addition to harvesting personal data from compromised accounts.
The malicious actors used SMS messages that pretended to be the messaging service’s official support bot. Those texts urged recipients to reveal their account credentials or take actions that would hand over control of their accounts.
The SSU emphasized that the assaults did not only aim at institutions, public figures or officials, but also impacted the private messaging accounts of ordinary Ukrainian citizens. The agency did not link the campaign to any single named hacking collective in its announcement.
However, the bulletin noted that comparable waves of targeting against Signal and WhatsApp users have previously been linked to Russian-aligned threat clusters tracked under names such as Star Blizzard, UNC5792 (also known as UAC-0195) and UNC4221 (also known as UAC-0185).
To reduce exposure to these schemes, the SSU and cybersecurity advisers recommend routinely checking active sessions in messaging apps and signing out any unfamiliar connections, enabling two-factor authentication (2FA), avoiding scanning QR codes sent by unknown contacts, and never sharing confirmation codes, PINs, passwords or account recovery keys. They also warned against clicking suspicious links or opening files received from untrusted chats.
The disclosure follows a related FBI advisory that attributed Russian Intelligence Services (RIS) actors to an ongoing phishing campaign that targets users of commercial messaging applications, attempting to trick high-value victims into surrendering backup recovery keys.
Separately, late last month Ukraine’s Computer Emergency Response Team (CERT-UA) attributed a spear-phishing operation to the Belarus-aligned actor UNC1151 (also tracked as Ghostwriter and UAC-0057). That campaign used compromised email accounts to deliver an information-stealing malware known as OYSTERBLUES to government organizations.