State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151)

State-Sponsored Signal Messenger Hijacking (TL-2026-0111) is a high-severity advanced persistent threat campaign, first published 2026-02-16. It is attributed to Sandworm (Russia, Belarus) with high confidence, maps to 28 MITRE ATT&CK techniques (T1005, T1021.002, T1030), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-0111

Threat ID
TL-2026-0111
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-02-16
Last reviewed
2026-02-16
Attribution
Sandworm
Attribution confidence
HIGH
Nation-state nexus
Russia, Belarus
Motivation
ESPIONAGE
Target sectors
Military, Government, Defense, Journalism, Activists, Humanitarian Organizations
Target regions
Ukraine, Eastern Europe, Europe, Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in State-Sponsored Signal Messenger Hijacking

Malware and tooling: Chisel

Multiple Russia-aligned threat actors (APT44/Sandworm, UNC5792, UNC4221, Turla, UNC1151/Belarus) conducting coordinated campaigns to compromise Signal Messenger accounts via QR code phishing that abuses Signal's 'Linked Devices' feature, plus direct Signal database exfiltration via WAVESIGN, Infamous Chisel, and PowerShell/Robocopy tools. Driven by Russia-Ukraine wartime intelligence demands.

How State-Sponsored Signal Messenger Hijacking works

Google Threat Intelligence Group (GTIG) published a comprehensive report in February 2025 documenting escalating Russian state-aligned campaigns targeting Signal Messenger. The attacks exploit Signal's legitimate 'Linked Devices' feature to achieve real-time message interception without full device compromise — a novel, low-signature technique likely to proliferate beyond the Ukraine theater.

**V1 CORRECTION: The v1 title claims 'EU Officials' as primary targets. This is INACCURATE/INFLATED. GTIG documents primary targeting of Ukrainian military personnel (specifically users of the Kropyva artillery guidance app), plus politicians, journalists, activists, and other at-risk communities. While EU officials using Signal may be at risk, the DOCUMENTED targeting is overwhelmingly Ukraine-focused in the context of Russia's invasion. No specific EU official compromise incidents are documented in any primary source.**

**THE LINKED DEVICES ATTACK:** The core technique abuses Signal's QR code-based device linking. Threat actors craft malicious QR codes that, when scanned by a victim, silently link the victim's Signal account to an attacker-controlled Signal instance. Once linked, ALL future messages are delivered synchronously to both victim and attacker in real-time. This provides persistent eavesdropping without any malware on the victim's device — no indicators on the endpoint, no compromise to detect. GTIG describes this as 'a low-signature form of initial access' with 'high risk that a compromise can go unnoticed for extended periods.'

**THREAT ACTOR BREAKDOWN (5 groups documented):**

1. **UNC5792** (overlaps CERT-UA UAC-0195) — Modified legitimate Signal group invite pages. Replaced JavaScript redirect code from 'sgnl://signal.group/' to 'sgnl://linkdevice?uuid=' URI. Hosted on actor-controlled domains like signal-groups[.]tech. Victims think they're joining a group; instead they're linking their account to the attacker.

2. **UNC4221** (CERT-UA UAC-0185) — Developed a custom Signal phishing kit mimicking the Kropyva artillery guidance application used by the Armed Forces of Ukraine. Multiple variations: (a) phishing sites redirecting to fake Signal device-linking instructions, (b) QR codes embedded directly in Kropyva-themed pages, (c) earlier 2022 operations using fake Signal security alerts. Also deployed PINPOINT JavaScript payload for geolocation collection via browser GeoLocation API.

3. **APT44 / Sandworm** (GRU, Main Centre for Special Technologies/GTsST) — Two operational modes: (a) Close-access operations enabling forward-deployed Russian military forces to link Signal accounts on BATTLEFIELD-CAPTURED DEVICES back to attacker infrastructure, (b) WAVESIGN Windows Batch script that queries Signal's SQLite database, decrypts messages using sqlcipher, and exfiltrates via Rclone.

4. **Turla** (FSB, Center 16) — Lightweight PowerShell script targeting Signal Desktop. Stages config.json and db.sqlite from %APPDATA%\Roaming\Signal, compresses to ZIP, copies to network share for exfiltration.

5. **UNC1151** (Belarus-linked) — Uses Robocopy to stage Signal Desktop directories (messages + attachments) to C:\Users\Public\data\signa for later exfiltration.

**ADDITIONAL TOOL — INFAMOUS CHISEL:** Android malware attributed to Sandworm (SSU Ukraine + UK NCSC, 2023). Recursively searches Android devices for Signal database files and other messaging app data. Designed for battlefield device exploitation.

**SIGNAL'S RESPONSE:** Signal cooperated with GTIG on the investigation and released hardened features on both Android and iOS to help protect against device-linking phishing. Users should update to the latest Signal version.

**BROADER IMPLICATIONS:** GTIG warns this tradecraft will: (1) grow in prevalence, (2) proliferate to additional threat actors outside Ukraine, (3) extend to WhatsApp and Telegram which are also being targeted. The attack class — abusing legitimate multi-device features — represents a fundamental challenge because no centralized detection exists for unauthorized device linking.

MITRE ATT&CK techniques used in TL-2026-0111

collection

T1005 Data from Local System; T1074.001 Local Data Staging; T1119 Automated Collection; T1213 Data from Information Repositories; T1560.001 Archive via Utility

lateral-movement

T1021.002 SMB/Windows Admin Shares

exfiltration

T1030 Data Transfer Size Limits; T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage

defense-evasion

T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion

execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.007 JavaScript

discovery

T1082 System Information Discovery; T1518 Software Discovery; T1614 System Location Discovery

persistence

T1098.001 Additional Cloud Credentials; T1098.005 Device Registration

command-and-control

T1102 Web Service

initial-access

T1199 Trusted Relationship; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service

credential-access

T1528 Steal Application Access Token

impact

T1531 Account Access Removal

resource-development

T1583.001 Domains; T1608.005 Link Target

Remediation for State-Sponsored Signal Messenger Hijacking

Patches

  • Signal Android + iOS hardened device-linking (Feb 2025)

Immediate actions

  • Update Signal to latest version (Android + iOS) — contains hardened device-linking protections released in cooperation with GTIG
  • Audit Signal Linked Devices: Settings → Linked Devices — remove any unrecognized devices immediately
  • Do NOT scan QR codes from untrusted sources claiming to be Signal group invites or security alerts
  • Block known phishing domains: signal-groups[.]tech, signal-confirm[.]site, signal-protect[.]host, teneta.add-group[.]site
  • Military/government organizations: brief personnel on QR code phishing targeting Signal

Workarounds

  • Regularly check Signal → Settings → Linked Devices and remove any unknown entries
  • Do not scan Signal QR codes from web links — only scan from physical devices you trust
  • For high-risk personnel: disable Signal Desktop entirely and use mobile-only

Longer-term hardening

  • Deploy organizational MDM policies requiring Signal updates to latest hardened versions
  • Implement monitoring for Signal Desktop database access: watch for processes reading %APPDATA%\Roaming\Signal\sql\db.sqlite and config.json
  • Monitor for Rclone, Robocopy, and PowerShell commands targeting Signal directories
  • Implement browser-based geolocation API abuse detection (PINPOINT payload indicator)
  • Security awareness training: QR code phishing is a growing attack vector — brief at-risk personnel
  • Consider using Signal's screen lock and registration PIN features for additional protection

Timeline of State-Sponsored Signal Messenger Hijacking

  • UNC4221 (UAC-0185) begins early Signal phishing operations using fake Signal security alert pages (signal-protect[.]host domain). Targets Ukrainian military Signal users. Source: https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger
  • UNC5792 (UAC-0195) deploys modified Signal group invite pages that replace JavaScript redirect from sgnl://signal.group/ to sgnl://linkdevice?uuid=. Hosted on signal-groups[.]tech. Victims link their accounts to attacker-controlled Signal instances. Source: GTIG/CERT-UA.
  • SSU Ukraine and UK NCSC jointly disclose Infamous Chisel Android malware attributed to Sandworm/APT44. Designed to recursively search for Signal database files and other messaging app data on Android devices captured in the Ukraine conflict. Source: https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/infamous-chisel/NCSC-MAR-Infamous-Chisel.pdf
  • Google Threat Intelligence publishes comprehensive APT44/Sandworm profile. Documents GRU GTsST attribution and battlefield-level cyber operations including Signal account capture from devices seized in combat. Source: https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm
  • UNC4221 deploys tailored Signal phishing kit mimicking Kropyva artillery guidance application. QR codes embedded in fake Kropyva pages (teneta.add-group[.]site). Also deploys PINPOINT JavaScript payload for geolocation collection. Source: GTIG.
  • CERT-UA publishes advisory on UAC-0195 (overlapping UNC5792) Signal account compromise via modified group invites. Source: https://cert.gov.ua/article/6278735
  • CERT-UA publishes advisory on UAC-0185 (UNC4221) Signal phishing kit targeting Ukrainian military. Source: https://cert.gov.ua/article/6281632
  • Signal releases hardened device-linking protections on both Android and iOS in cooperation with GTIG investigation. Designed to help protect against QR code phishing campaigns abusing the Linked Devices feature. Source: GTIG.
  • Google Threat Intelligence Group (Dan Black) publishes 'Signals of Trouble' report documenting 5 Russian-aligned threat actors targeting Signal. Warns technique will proliferate beyond Ukraine. Source: https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger
  • As of 2026-05-29, this Russia-aligned campaign (Star Blizzard, UNC5792, UNC4221, APT44) remains ACTIVE: a joint FBI/CISA warning (Mar 21 2026) and Dutch MIVD/AIVD alert report ongoing global abuse of Signal/WhatsApp linked-devices QR phishing, with thousands of accounts compromised. No CVE exists (social-engineering technique), so Signal's Feb 2025 hardening reduced but did not end exploitation.

Sources cited for State-Sponsored Signal Messenger Hijacking

More in apt

Detection coverage for TL-2026-0111

As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0111 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats