Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover — Threadlinqs Intelligence
As of 2026-08-02, Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover is a high-severity phishing threat attributed to UNC5792 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1814 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: UNC5792 · Russia · ESPIONAGE
FBI- and CISA-attributed Russian intelligence clusters UNC5792 (FSB Border Guards) and UNC4221 (GRU) are impersonating Signal support in-app to trick high-value targets into pasting their 64-character
Since at least 2024, Google Threat Intelligence Group (GTIG) has tracked a cluster of Russia state-aligned actors — publicly designated UNC5792 (overlapping CERT-UA's UAC-0195, attributed by the FBI to FSB Border Guards officers) and UNC4221 (overlapping CERT-UA's UAC-0185, attributed to Russian military/GRU services) — running an evolving social-engineering campaign against Signal, WhatsApp, and Telegram users of intelligence value: government officials, military personnel, political figures, journalists, activists, and Ukrainian leadership.
The campaign has moved through three documented phases. In its first phase (reported in an FBI/CISA PSA around March 2026, PSA260320), operators phished SMS verification codes and account PINs to hijack accounts outright. A parallel and earlier-documented technique, detailed in GTIG's February 19, 2025 report 'Signals of Trouble,' abused Signal's legitimate linked-device feature: UNC5792 altered legitimate Signal 'group invite' web pages, replacing the benign sgnl://signal.group/ redirect JavaScript with a malicious sgnl://linkdevice?uuid=...&pub_key=... URI that silently authorizes an attacker-controlled device to link to the victim's account, enabling real-time, low-signature eavesdropping on all future messages without any device exploit. UNC4221 ran a parallel operation using a phishing kit that impersonates Kropyva, a tactical artillery-guidance and minefield-mapping application used by the Armed Forces of Ukraine, embedding malicious device-linking QR codes directly into Kropyva-themed pages and deploying a lightweight JavaScript reconnaissance payload tracked as PINPOINT that harvests basic user information and precise geolocation via the browser GeoLocation API.
By May-June 2026, both clusters pivoted to a third and more damaging technique: soliciting the victim's Signal Secure Backup Recovery Key directly. Posing as an automated 'Signal Support' account with a spoofed display name and avatar, operators send a first message claiming a joint investigation uncovered 'account attacks from hackers in Iran and post-Soviet countries' and announcing a mandatory two-factor-verification rollout, then follow up with an urgent 'sync issue' warning that chats and media are about to be lost. Victims are walked step-by-step through Settings > Backups > Enable Backups > View Recovery Key, told to copy the 64-character key, and paste it directly into the chat with the impersonated 'support' account. Once obtained, the key lets the attacker restore the victim's full encrypted backup — including historical private and group message content that is not otherwise retrievable from Signal's servers — to a device they control, and to subsequently take over the account.
The underlying design flaw that makes this so damaging is cryptographic: Signal's Secure Backups (rolled out from September 2025, reaching all users by roughly February 2026) protect the archive with a single static recovery key that is never automatically rotated or ratcheted forward. A single disclosure at any point exposes the entire backup history with no bounded exposure window and no self-healing after compromise — the key keeps working against a freshly created account on the same phone number until the user manually regenerates it. An IACR preprint from IISc Bangalore, reported July 27, 2026, proposes STEBR, a three-layer fix using timed key erasure and Shamir secret sharing, but no formal patch had shipped as of this writing.
On June 26, 2026 the FBI and CISA jointly updated their advisory (PSA I-062626-PSA / PSA260626) to formally name UNC5792 and UNC4221 and describe the recovery-key pivot; Ukraine's SBU issued a coordinated joint disclosure the same day, and the State Department's Rewards for Justice program announced a reward of up to $10 million for information on UNC5792. Dutch (AIVD, MIVD), German (BfV, BSI), and French (ANSSI) services issued parallel warnings. No CVE applies — this is not an exploit against Signal's
Weaknesses (CWE)
CWE-640, CWE-522
Target sectors: government administration, military, defense, ngo, news - media, diplomatic, think-tank
Target regions: ukraine, united states of america, Europe, moldova, georgia, france
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583.001, T1585.001, T1587.001, T1608.001, T1598.003, T1598.004, T1566.002, T1566.003, T1204.001, T1036.005