Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp Linked-Device and OAuth Account Takeover
Russian State-Backed UNC5792/UNC4221 Phish EU Officials (TL-2026-2170) is a high-severity phishing campaign, first published 2026-08-26. It is attributed to UNC5792 (Russia) with high confidence, affects Signal Technology Foundation Signal Messenger, maps to 13 MITRE ATT&CK techniques (T1078, T1111, T1123), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2170
- Threat ID
- TL-2026-2170
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-26
- Last reviewed
- 2026-08-26
- Attribution
- UNC5792
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomatic, military, defense, news - media, ngo, academia, think-tank
- Target regions
- netherlands, European Union, ukraine, united states of america, NATO member states, armenia
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Russian State-Backed UNC5792/UNC4221 Phish EU Officials
Malware and tooling: Atomic (AMOS), ChocoShell (CHERRYPIE), CornFlake RAT, HEADRUSH, Kazuar - S0265, Vidar, ENGINELIGHT, FruitStone (CloudSync Console), Turla
Dutch intelligence services AIVD and MIVD, later joined by FBI/CISA and a $10M US Rewards for Justice bounty, attribute a sustained account-takeover campaign against senior EU/NATO officials, diplomats, military personnel, journalists, and Russia-focused researchers to Russian state actors tracked as UNC5792 (FSB) and UNC4221 (Russian military intelligence), with overlapping Google-tracked clusters UNC6293/UNC7005/UNC5976. Attackers do not break Signal or WhatsApp encryption; they social-engineer victims into approving a malicious linked device or handing over verification codes, PINs, and — since mid-2026 — Signal Backup Recovery Keys, giving real-time mirrored access to messages.
How Russian State-Backed UNC5792/UNC4221 Phish EU Officials works
Since at least June 2025, Google's Threat Intelligence Group has tracked UNC6293 (a sub-cluster of ICE RELIC/APT29, 'Cozy Bear', linked to Russia's SVR) impersonating US State Department personnel to lure diplomats and Russia researchers into phishing flows. By March 2026 the operation had scaled into a global campaign: Dutch AIVD and MIVD publicly attributed it to Russian state actors, describing attackers who pose as 'Signal Security Support ChatBot' or a similar official-sounding account, warn victims of 'suspicious activity' or a 'possible data leak', and trick them into (a) sharing an SMS verification code and PIN so the attacker can register a new linked device under the victim's account, or (b) scanning a QR code / approving a WhatsApp 'linked devices' request directly. Because the underlying end-to-end encryption is never broken, victims regain access to their own account normally and often have no indication of compromise while the attacker continues to mirror every message in real time.
Google TIG and Microsoft (tracking an overlapping cluster as Storm-2945/UNC7005) documented a parallel, distinct cluster, UNC5976, running hospitality-themed operations: 'CaptiveCrunch' compromised hotel and conference-center Wi-Fi captive portals (~70 victim IPs identified) to redirect traveling diplomats and defense-industry personnel into phishing pages, and used diplomatic-event lures (a GLOBSEC forum spoof and a 'Summit Companion App' theme, May-June 2026) to distribute a rogue Excel plugin (HEADRUSH) that drops an HTA payload, and commodity/custom malware — Vidar (Windows), Atomic/AMOS (macOS), CornFlake RAT (Go-based), and ChocoShell/CHERRYPIE (PowerShell) — for post-compromise credential and file theft, tasked from a web-based C2 panel branded 'FruitStone/CloudSync Console' to blend in as a legitimate cloud-sync product.
From June 2026 the FBI observed the TTP evolve: rather than one-time verification codes, UNC5792/UNC4221 began directly soliciting victims' Signal Backup Recovery Key — the credential that decrypts a user's entire local message history — via chat, framed as a mandatory 2FA rollout or urgent data-recovery request. The FBI/CISA updated advisory (PSA I-062626-PSA, 2026-06-26) and the US State Department's subsequent $10M Rewards for Justice offer (2026-06-29) formally named UNC5792 as affiliated with FSB Border Guards and UNC4221 with Russian military intelligence, confirming thousands of compromised government, military, journalist, and NGO accounts across the US, NATO member states, Ukraine, and allied intelligence partners. In parallel, Google TIG documented the same actor set (August 2026) expanding into OAuth device-code phishing — fake 'Continue with Google/Microsoft' pages that capture a legitimate authentication token after a real login, rather than a stolen password — against academia, aerospace, defense, and think-tank targets. A separate but related Russian FSB (Center 16) group, Secret Blizzard/Turla, was independently found repurposing its long-running Kazuar backdoor (evolved into a modular, ~150-option P2P botnet) specifically to exfiltrate Signal Desktop message-history files from compromised Windows hosts, illustrating a second, malware-based route to the same messaging-app data. The EU Interinstitutional Cybersecurity Board's August 2026 threat-landscape briefing (reported by Euronews) folded this Signal/WhatsApp campaign into its broader count of 190+ threat actors targeting the EU ecosystem and 8 significant incidents logged in H1 2026, confirming Dutch government personnel among the victims and stating the attackers 'likely gained access to sensitive information.' There is no PoC/exploit code involved — the entire chain is social-engineering and legitimate-feature abuse (linked devices, OAuth device-code flow, backup key export), not a software vulnerability. Signal shipped a cryptographic hardening fix to the backup-key flow on 2026-07-27 in direct response to the FBI disclosure.
MITRE ATT&CK techniques used in TL-2026-2170
Initial Access
T1078 Valid Accounts; T1566 Phishing
Credential Access
T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation
Collection
lateral-movement
T1550 Use Alternate Authentication Material
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Affected products and versions in Russian State-Backed UNC5792/UNC4221 Phish EU Officials
- Signal Technology Foundation — Signal Messenger
Vulnerable versions: all versions — legitimate 'linked devices' and backup-key export features abused via social engineering, not a code vulnerability
Fixed in: backup recovery key flow cryptographically hardened 2026-07-27 - Meta — WhatsApp
Vulnerable versions: all versions — legitimate 'linked devices' feature abused via social engineering
Fixed in: N/A — no vendor fix disclosed
Remediation for Russian State-Backed UNC5792/UNC4221 Phish EU Officials
Patches
- Signal shipped a cryptographic hardening fix to the backup recovery key flow on 2026-07-27 in direct response to this campaign
Immediate actions
- Generate a new Signal backup recovery key immediately (Settings > Chats > Chat Backups) to invalidate any key an attacker may already hold
- Review Signal and WhatsApp 'Linked Devices' lists and remove any unrecognized device
- Treat any in-app message from 'Signal Support', 'Signal Security Support ChatBot', or similar as hostile — never share verification codes, PINs, or backup recovery keys through chat
- Verify unexpected diplomatic/conference invitations and any OAuth 'Continue with Google/Microsoft' login prompt via an out-of-band channel before entering credentials
Workarounds
- Disable or restrict the 'linked devices' feature where operationally possible for high-risk personnel
- Require out-of-band verbal or video confirmation before accepting any new linked-device request
Longer-term hardening
- Move classified, confidential, or sensitive government communications off consumer messaging apps entirely, per MIVD guidance
- Deploy phishing-resistant, hardware-bound authentication (FIDO2/WebAuthn) for accounts belonging to high-value personnel
- Run targeted awareness training on linked-device and OAuth device-code phishing pretexts for diplomats, journalists, NGO staff, and defense personnel
- Monitor group chats for duplicate member entries or unrecognized display names as an account-compromise indicator
Timeline of Russian State-Backed UNC5792/UNC4221 Phish EU Officials
- Google Threat Intelligence Group first documents UNC6293 (ICE RELIC/APT29 sub-cluster) impersonating US State Department personnel to phish diplomats and Russia researchers.
- Germany's BSI/BfV issue an alert on phishing campaigns 'likely linked to state-controlled actors'; Google TIG separately identifies the UNC7005/Storm-2945 cluster.
- Dutch AIVD and MIVD publicly attribute a large-scale Signal/WhatsApp linked-device and verification-code phishing campaign to Russian state actors, confirming compromised Dutch government personnel.
- FBI and CISA issue a joint advisory corroborating the Dutch findings and warning of thousands of compromised commercial messaging accounts.
- UNC5976's 'CaptiveCrunch' hotel/conference Wi-Fi captive-portal hijacking infrastructure is observed redirecting travelers into phishing flows.
- Amnesty International Security Lab researcher Donncha Ó Cearbhaill discloses identifying more than 13,500 targets of the campaign via a 'snowball' contact-mining methodology, per TechCrunch.
- UNC5976 runs a GLOBSEC forum spoof and 'Summit Companion App' lure to distribute the HEADRUSH Excel-plugin malware and commodity infostealers.
- FBI issues updated advisory PSA I-062626-PSA describing a shift from one-time verification-code theft to direct solicitation of victims' Signal Backup Recovery Keys.
- US State Department's Rewards for Justice program posts a $10 million reward for information on UNC5792 (FSB Border Guards) and UNC4221 (Russian military intelligence) members.
- Signal ships a cryptographic hardening fix to the backup recovery key flow in direct response to the disclosed campaign.
- Google TIG and reporting describe the same actor set expanding into OAuth device-code phishing against academia, aerospace, defense, and think-tank targets.
- EU Interinstitutional Cybersecurity Board's threat-landscape briefing folds the campaign into its count of 190+ threat actors and 8 significant H1 2026 incidents targeting the EU ecosystem, confirming compromised Dutch government personnel.
Sources cited for Russian State-Backed UNC5792/UNC4221 Phish EU Officials
- State actors tried to hack EU officials' messaging apps, cybersecurity body warns
- Russia targets Signal and WhatsApp accounts in cyber campaign
- Russian government hackers targeting Signal and WhatsApp users, Dutch spies warn
- Russian hackers go after high-value targets through Signal
- Spyware Investigator Exposes 13,500-Target Russian Signal Hijack
- FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
- US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
- Russian snoops add OAuth abuse to targeted phishing campaigns
- Fake Conferences, OAuth and WhatsApp: Inside Russia's New Espionage Tactics
- Russian hackers turn Kazuar backdoor into modular P2P botnet
- Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine
- US offers $10M reward for Russian hackers who steal Signal backup keys
- Cybersecurity Advisory: Phishing via messaging apps Signal and WhatsApp
More in phishing
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
Detection coverage for TL-2026-2170
As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2170 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.