State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151) — Threadlinqs Intelligence
As of 2026-05-30, State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151) is a high-severity apt threat attributed to Sandworm (Russia, Belarus), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-0111 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Sandworm · Russia, Belarus · ESPIONAGE
Multiple Russia-aligned threat actors (APT44/Sandworm, UNC5792, UNC4221, Turla, UNC1151/Belarus) conducting coordinated campaigns to compromise Signal Messenger accounts via QR code phishing that
Google Threat Intelligence Group (GTIG) published a comprehensive report in February 2025 documenting escalating Russian state-aligned campaigns targeting Signal Messenger. The attacks exploit Signal's legitimate 'Linked Devices' feature to achieve real-time message interception without full device compromise — a novel, low-signature technique likely to proliferate beyond the Ukraine theater.
**V1 CORRECTION: The v1 title claims 'EU Officials' as primary targets. This is INACCURATE/INFLATED. GTIG documents primary targeting of Ukrainian military personnel (specifically users of the Kropyva artillery guidance app), plus politicians, journalists, activists, and other at-risk communities. While EU officials using Signal may be at risk, the DOCUMENTED targeting is overwhelmingly Ukraine-focused in the context of Russia's invasion. No specific EU official compromise incidents are documented in any primary source.**
**THE LINKED DEVICES ATTACK:**
The core technique abuses Signal's QR code-based device linking. Threat actors craft malicious QR codes that, when scanned by a victim, silently link the victim's Signal account to an attacker-controlled Signal instance. Once linked, ALL future messages are delivered synchronously to both victim and attacker in real-time. This provides persistent eavesdropping without any malware on the victim's device — no indicators on the endpoint, no compromise to detect. GTIG describes this as 'a low-signature form of initial access' with 'high risk that a compromise can go unnoticed for extended periods.'
**THREAT ACTOR BREAKDOWN (5 groups documented):**
1. **UNC5792** (overlaps CERT-UA UAC-0195) — Modified legitimate Signal group invite pages. Replaced JavaScript redirect code from 'sgnl://signal.group/' to 'sgnl://linkdevice?uuid=' URI. Hosted on actor-controlled domains like signal-groups[.]tech. Victims think they're joining a group; instead they're linking their account to the attacker.
2. **UNC4221** (CERT-UA UAC-0185) — Developed a custom Signal phishing kit mimicking the Kropyva artillery guidance application used by the Armed Forces of Ukraine. Multiple variations: (a) phishing sites redirecting to fake Signal device-linking instructions, (b) QR codes embedded directly in Kropyva-themed pages, (c) earlier 2022 operations using fake Signal security alerts. Also deployed PINPOINT JavaScript payload for geolocation collection via browser GeoLocation API.
3. **APT44 / Sandworm** (GRU, Main Centre for Special Technologies/GTsST) — Two operational modes: (a) Close-access operations enabling forward-deployed Russian military forces to link Signal accounts on BATTLEFIELD-CAPTURED DEVICES back to attacker infrastructure, (b) WAVESIGN Windows Batch script that queries Signal's SQLite database, decrypts messages using sqlcipher, and exfiltrates via Rclone.
4. **Turla** (FSB, Center 16) — Lightweight PowerShell script targeting Signal Desktop. Stages config.json and db.sqlite from %APPDATA%\Roaming\Signal, compresses to ZIP, copies to network share for exfiltration.
5. **UNC1151** (Belarus-linked) — Uses Robocopy to stage Signal Desktop directories (messages + attachments) to C:\Users\Public\data\signa for later exfiltration.
**ADDITIONAL TOOL — INFAMOUS CHISEL:**
Android malware attributed to Sandworm (SSU Ukraine + UK NCSC, 2023). Recursively searches Android devices for Signal database files and other messaging app data. Designed for battlefield device exploitation.
**SIGNAL'S RESPONSE:**
Signal cooperated with GTIG on the investigation and released hardened features on both Android and iOS to help protect against device-linking phishing. Users should update to the latest Signal version.
**BROADER IMPLICATIONS:**
GTIG warns this tradecraft will: (1) grow in prevalence, (2) proliferate to additional threat actors outside Ukraine, (3) extend to WhatsApp and Telegram which are also being targeted. The attack class — abusing legitimate multi-device features — represents a fundamental challenge
Target sectors: Military, Government, Defense, Journalism, Activists, Humanitarian Organizations
Target regions: Ukraine, Eastern Europe, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566.002, T1566.003, T1098.001, T1005, T1213, T1560.001, T1036.005, T1082, T1614, T1059.001