State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151)
State-Sponsored Signal Messenger Hijacking (TL-2026-0111) is a high-severity advanced persistent threat campaign, first published 2026-02-16. It is attributed to Sandworm (Russia, Belarus) with high confidence, maps to 28 MITRE ATT&CK techniques (T1005, T1021.002, T1030), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-0111
- Threat ID
- TL-2026-0111
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-02-16
- Last reviewed
- 2026-02-16
- Attribution
- Sandworm
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia, Belarus
- Motivation
- ESPIONAGE
- Target sectors
- Military, Government, Defense, Journalism, Activists, Humanitarian Organizations
- Target regions
- Ukraine, Eastern Europe, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in State-Sponsored Signal Messenger Hijacking
Malware and tooling: Chisel
Multiple Russia-aligned threat actors (APT44/Sandworm, UNC5792, UNC4221, Turla, UNC1151/Belarus) conducting coordinated campaigns to compromise Signal Messenger accounts via QR code phishing that abuses Signal's 'Linked Devices' feature, plus direct Signal database exfiltration via WAVESIGN, Infamous Chisel, and PowerShell/Robocopy tools. Driven by Russia-Ukraine wartime intelligence demands.
How State-Sponsored Signal Messenger Hijacking works
Google Threat Intelligence Group (GTIG) published a comprehensive report in February 2025 documenting escalating Russian state-aligned campaigns targeting Signal Messenger. The attacks exploit Signal's legitimate 'Linked Devices' feature to achieve real-time message interception without full device compromise — a novel, low-signature technique likely to proliferate beyond the Ukraine theater.
**V1 CORRECTION: The v1 title claims 'EU Officials' as primary targets. This is INACCURATE/INFLATED. GTIG documents primary targeting of Ukrainian military personnel (specifically users of the Kropyva artillery guidance app), plus politicians, journalists, activists, and other at-risk communities. While EU officials using Signal may be at risk, the DOCUMENTED targeting is overwhelmingly Ukraine-focused in the context of Russia's invasion. No specific EU official compromise incidents are documented in any primary source.**
**THE LINKED DEVICES ATTACK:** The core technique abuses Signal's QR code-based device linking. Threat actors craft malicious QR codes that, when scanned by a victim, silently link the victim's Signal account to an attacker-controlled Signal instance. Once linked, ALL future messages are delivered synchronously to both victim and attacker in real-time. This provides persistent eavesdropping without any malware on the victim's device — no indicators on the endpoint, no compromise to detect. GTIG describes this as 'a low-signature form of initial access' with 'high risk that a compromise can go unnoticed for extended periods.'
**THREAT ACTOR BREAKDOWN (5 groups documented):**
1. **UNC5792** (overlaps CERT-UA UAC-0195) — Modified legitimate Signal group invite pages. Replaced JavaScript redirect code from 'sgnl://signal.group/' to 'sgnl://linkdevice?uuid=' URI. Hosted on actor-controlled domains like signal-groups[.]tech. Victims think they're joining a group; instead they're linking their account to the attacker.
2. **UNC4221** (CERT-UA UAC-0185) — Developed a custom Signal phishing kit mimicking the Kropyva artillery guidance application used by the Armed Forces of Ukraine. Multiple variations: (a) phishing sites redirecting to fake Signal device-linking instructions, (b) QR codes embedded directly in Kropyva-themed pages, (c) earlier 2022 operations using fake Signal security alerts. Also deployed PINPOINT JavaScript payload for geolocation collection via browser GeoLocation API.
3. **APT44 / Sandworm** (GRU, Main Centre for Special Technologies/GTsST) — Two operational modes: (a) Close-access operations enabling forward-deployed Russian military forces to link Signal accounts on BATTLEFIELD-CAPTURED DEVICES back to attacker infrastructure, (b) WAVESIGN Windows Batch script that queries Signal's SQLite database, decrypts messages using sqlcipher, and exfiltrates via Rclone.
4. **Turla** (FSB, Center 16) — Lightweight PowerShell script targeting Signal Desktop. Stages config.json and db.sqlite from %APPDATA%\Roaming\Signal, compresses to ZIP, copies to network share for exfiltration.
5. **UNC1151** (Belarus-linked) — Uses Robocopy to stage Signal Desktop directories (messages + attachments) to C:\Users\Public\data\signa for later exfiltration.
**ADDITIONAL TOOL — INFAMOUS CHISEL:** Android malware attributed to Sandworm (SSU Ukraine + UK NCSC, 2023). Recursively searches Android devices for Signal database files and other messaging app data. Designed for battlefield device exploitation.
**SIGNAL'S RESPONSE:** Signal cooperated with GTIG on the investigation and released hardened features on both Android and iOS to help protect against device-linking phishing. Users should update to the latest Signal version.
**BROADER IMPLICATIONS:** GTIG warns this tradecraft will: (1) grow in prevalence, (2) proliferate to additional threat actors outside Ukraine, (3) extend to WhatsApp and Telegram which are also being targeted. The attack class — abusing legitimate multi-device features — represents a fundamental challenge because no centralized detection exists for unauthorized device linking.
MITRE ATT&CK techniques used in TL-2026-0111
collection
T1005 Data from Local System; T1074.001 Local Data Staging; T1119 Automated Collection; T1213 Data from Information Repositories; T1560.001 Archive via Utility
lateral-movement
T1021.002 SMB/Windows Admin Shares
exfiltration
T1030 Data Transfer Size Limits; T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage
defense-evasion
T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion
execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.007 JavaScript
discovery
T1082 System Information Discovery; T1518 Software Discovery; T1614 System Location Discovery
persistence
T1098.001 Additional Cloud Credentials; T1098.005 Device Registration
command-and-control
initial-access
T1199 Trusted Relationship; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service
credential-access
T1528 Steal Application Access Token
impact
resource-development
Remediation for State-Sponsored Signal Messenger Hijacking
Patches
- Signal Android + iOS hardened device-linking (Feb 2025)
Immediate actions
- Update Signal to latest version (Android + iOS) — contains hardened device-linking protections released in cooperation with GTIG
- Audit Signal Linked Devices: Settings → Linked Devices — remove any unrecognized devices immediately
- Do NOT scan QR codes from untrusted sources claiming to be Signal group invites or security alerts
- Block known phishing domains: signal-groups[.]tech, signal-confirm[.]site, signal-protect[.]host, teneta.add-group[.]site
- Military/government organizations: brief personnel on QR code phishing targeting Signal
Workarounds
- Regularly check Signal → Settings → Linked Devices and remove any unknown entries
- Do not scan Signal QR codes from web links — only scan from physical devices you trust
- For high-risk personnel: disable Signal Desktop entirely and use mobile-only
Longer-term hardening
- Deploy organizational MDM policies requiring Signal updates to latest hardened versions
- Implement monitoring for Signal Desktop database access: watch for processes reading %APPDATA%\Roaming\Signal\sql\db.sqlite and config.json
- Monitor for Rclone, Robocopy, and PowerShell commands targeting Signal directories
- Implement browser-based geolocation API abuse detection (PINPOINT payload indicator)
- Security awareness training: QR code phishing is a growing attack vector — brief at-risk personnel
- Consider using Signal's screen lock and registration PIN features for additional protection
Timeline of State-Sponsored Signal Messenger Hijacking
- UNC4221 (UAC-0185) begins early Signal phishing operations using fake Signal security alert pages (signal-protect[.]host domain). Targets Ukrainian military Signal users. Source: https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger
- UNC5792 (UAC-0195) deploys modified Signal group invite pages that replace JavaScript redirect from sgnl://signal.group/ to sgnl://linkdevice?uuid=. Hosted on signal-groups[.]tech. Victims link their accounts to attacker-controlled Signal instances. Source: GTIG/CERT-UA.
- SSU Ukraine and UK NCSC jointly disclose Infamous Chisel Android malware attributed to Sandworm/APT44. Designed to recursively search for Signal database files and other messaging app data on Android devices captured in the Ukraine conflict. Source: https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/infamous-chisel/NCSC-MAR-Infamous-Chisel.pdf
- Google Threat Intelligence publishes comprehensive APT44/Sandworm profile. Documents GRU GTsST attribution and battlefield-level cyber operations including Signal account capture from devices seized in combat. Source: https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm
- UNC4221 deploys tailored Signal phishing kit mimicking Kropyva artillery guidance application. QR codes embedded in fake Kropyva pages (teneta.add-group[.]site). Also deploys PINPOINT JavaScript payload for geolocation collection. Source: GTIG.
- CERT-UA publishes advisory on UAC-0195 (overlapping UNC5792) Signal account compromise via modified group invites. Source: https://cert.gov.ua/article/6278735
- CERT-UA publishes advisory on UAC-0185 (UNC4221) Signal phishing kit targeting Ukrainian military. Source: https://cert.gov.ua/article/6281632
- Signal releases hardened device-linking protections on both Android and iOS in cooperation with GTIG investigation. Designed to help protect against QR code phishing campaigns abusing the Linked Devices feature. Source: GTIG.
- Google Threat Intelligence Group (Dan Black) publishes 'Signals of Trouble' report documenting 5 Russian-aligned threat actors targeting Signal. Warns technique will proliferate beyond Ukraine. Source: https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger
- As of 2026-05-29, this Russia-aligned campaign (Star Blizzard, UNC5792, UNC4221, APT44) remains ACTIVE: a joint FBI/CISA warning (Mar 21 2026) and Dutch MIVD/AIVD alert report ongoing global abuse of Signal/WhatsApp linked-devices QR phishing, with thousands of accounts compromised. No CVE exists (social-engineering technique), so Signal's Feb 2025 hardening reduced but did not end exploitation.
Sources cited for State-Sponsored Signal Messenger Hijacking
- GTIG — Signals of Trouble: Russia-Aligned Actors Targeting Signal Messenger
- CERT-UA — UAC-0195 Signal Account Compromise Advisory
- CERT-UA — UAC-0185 Signal Phishing Kit Advisory
- UK NCSC — Infamous Chisel Malware Analysis Report
- SSU Ukraine — Russian Intelligence Targeting Armed Forces Communications
- GTIG — APT44: Unearthing Sandworm (GRU GTsST)
- US DOJ — Six Russian GRU Officers Charged (Sandworm)
- US DOJ — Snake Malware Network Disrupted (Turla/FSB)
- UK Gov — Russia FSB Malign Activity Factsheet (Turla Attribution)
- Signal — Linked Devices Feature Documentation
More in apt
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated Cyberattacks and Data Theft
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets
- Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During Operation Epic Fury
- China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI Models
- China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms ("One Target, Two Flags")
Detection coverage for TL-2026-0111
As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0111 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.