Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp Linked-Device and OAuth Account Takeover

Russian State-Backed UNC5792/UNC4221 Phish EU Officials (TL-2026-2170) is a high-severity phishing campaign, first published 2026-08-26. It is attributed to UNC5792 (Russia) with high confidence, affects Signal Technology Foundation Signal Messenger, maps to 13 MITRE ATT&CK techniques (T1078, T1111, T1123), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2170

Threat ID
TL-2026-2170
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-08-26
Last reviewed
2026-08-26
Attribution
UNC5792
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, diplomatic, military, defense, news - media, ngo, academia, think-tank
Target regions
netherlands, European Union, ukraine, united states of america, NATO member states, armenia
Detection rules
9
Indicators of compromise
17

Malware and tooling in Russian State-Backed UNC5792/UNC4221 Phish EU Officials

Malware and tooling: Atomic (AMOS), ChocoShell (CHERRYPIE), CornFlake RAT, HEADRUSH, Kazuar - S0265, Vidar, ENGINELIGHT, FruitStone (CloudSync Console), Turla

Dutch intelligence services AIVD and MIVD, later joined by FBI/CISA and a $10M US Rewards for Justice bounty, attribute a sustained account-takeover campaign against senior EU/NATO officials, diplomats, military personnel, journalists, and Russia-focused researchers to Russian state actors tracked as UNC5792 (FSB) and UNC4221 (Russian military intelligence), with overlapping Google-tracked clusters UNC6293/UNC7005/UNC5976. Attackers do not break Signal or WhatsApp encryption; they social-engineer victims into approving a malicious linked device or handing over verification codes, PINs, and — since mid-2026 — Signal Backup Recovery Keys, giving real-time mirrored access to messages.

How Russian State-Backed UNC5792/UNC4221 Phish EU Officials works

Since at least June 2025, Google's Threat Intelligence Group has tracked UNC6293 (a sub-cluster of ICE RELIC/APT29, 'Cozy Bear', linked to Russia's SVR) impersonating US State Department personnel to lure diplomats and Russia researchers into phishing flows. By March 2026 the operation had scaled into a global campaign: Dutch AIVD and MIVD publicly attributed it to Russian state actors, describing attackers who pose as 'Signal Security Support ChatBot' or a similar official-sounding account, warn victims of 'suspicious activity' or a 'possible data leak', and trick them into (a) sharing an SMS verification code and PIN so the attacker can register a new linked device under the victim's account, or (b) scanning a QR code / approving a WhatsApp 'linked devices' request directly. Because the underlying end-to-end encryption is never broken, victims regain access to their own account normally and often have no indication of compromise while the attacker continues to mirror every message in real time.

Google TIG and Microsoft (tracking an overlapping cluster as Storm-2945/UNC7005) documented a parallel, distinct cluster, UNC5976, running hospitality-themed operations: 'CaptiveCrunch' compromised hotel and conference-center Wi-Fi captive portals (~70 victim IPs identified) to redirect traveling diplomats and defense-industry personnel into phishing pages, and used diplomatic-event lures (a GLOBSEC forum spoof and a 'Summit Companion App' theme, May-June 2026) to distribute a rogue Excel plugin (HEADRUSH) that drops an HTA payload, and commodity/custom malware — Vidar (Windows), Atomic/AMOS (macOS), CornFlake RAT (Go-based), and ChocoShell/CHERRYPIE (PowerShell) — for post-compromise credential and file theft, tasked from a web-based C2 panel branded 'FruitStone/CloudSync Console' to blend in as a legitimate cloud-sync product.

From June 2026 the FBI observed the TTP evolve: rather than one-time verification codes, UNC5792/UNC4221 began directly soliciting victims' Signal Backup Recovery Key — the credential that decrypts a user's entire local message history — via chat, framed as a mandatory 2FA rollout or urgent data-recovery request. The FBI/CISA updated advisory (PSA I-062626-PSA, 2026-06-26) and the US State Department's subsequent $10M Rewards for Justice offer (2026-06-29) formally named UNC5792 as affiliated with FSB Border Guards and UNC4221 with Russian military intelligence, confirming thousands of compromised government, military, journalist, and NGO accounts across the US, NATO member states, Ukraine, and allied intelligence partners. In parallel, Google TIG documented the same actor set (August 2026) expanding into OAuth device-code phishing — fake 'Continue with Google/Microsoft' pages that capture a legitimate authentication token after a real login, rather than a stolen password — against academia, aerospace, defense, and think-tank targets. A separate but related Russian FSB (Center 16) group, Secret Blizzard/Turla, was independently found repurposing its long-running Kazuar backdoor (evolved into a modular, ~150-option P2P botnet) specifically to exfiltrate Signal Desktop message-history files from compromised Windows hosts, illustrating a second, malware-based route to the same messaging-app data. The EU Interinstitutional Cybersecurity Board's August 2026 threat-landscape briefing (reported by Euronews) folded this Signal/WhatsApp campaign into its broader count of 190+ threat actors targeting the EU ecosystem and 8 significant incidents logged in H1 2026, confirming Dutch government personnel among the victims and stating the attackers 'likely gained access to sensitive information.' There is no PoC/exploit code involved — the entire chain is social-engineering and legitimate-feature abuse (linked devices, OAuth device-code flow, backup key export), not a software vulnerability. Signal shipped a cryptographic hardening fix to the backup-key flow on 2026-07-27 in direct response to the FBI disclosure.

MITRE ATT&CK techniques used in TL-2026-2170

Initial Access

T1078 Valid Accounts; T1566 Phishing

Credential Access

T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation

Collection

T1123 Audio Capture

lateral-movement

T1550 Use Alternate Authentication Material

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Affected products and versions in Russian State-Backed UNC5792/UNC4221 Phish EU Officials

  • Signal Technology Foundation — Signal Messenger
    Vulnerable versions: all versions — legitimate 'linked devices' and backup-key export features abused via social engineering, not a code vulnerability
    Fixed in: backup recovery key flow cryptographically hardened 2026-07-27
  • Meta — WhatsApp
    Vulnerable versions: all versions — legitimate 'linked devices' feature abused via social engineering
    Fixed in: N/A — no vendor fix disclosed

Remediation for Russian State-Backed UNC5792/UNC4221 Phish EU Officials

Patches

  • Signal shipped a cryptographic hardening fix to the backup recovery key flow on 2026-07-27 in direct response to this campaign

Immediate actions

  • Generate a new Signal backup recovery key immediately (Settings > Chats > Chat Backups) to invalidate any key an attacker may already hold
  • Review Signal and WhatsApp 'Linked Devices' lists and remove any unrecognized device
  • Treat any in-app message from 'Signal Support', 'Signal Security Support ChatBot', or similar as hostile — never share verification codes, PINs, or backup recovery keys through chat
  • Verify unexpected diplomatic/conference invitations and any OAuth 'Continue with Google/Microsoft' login prompt via an out-of-band channel before entering credentials

Workarounds

  • Disable or restrict the 'linked devices' feature where operationally possible for high-risk personnel
  • Require out-of-band verbal or video confirmation before accepting any new linked-device request

Longer-term hardening

  • Move classified, confidential, or sensitive government communications off consumer messaging apps entirely, per MIVD guidance
  • Deploy phishing-resistant, hardware-bound authentication (FIDO2/WebAuthn) for accounts belonging to high-value personnel
  • Run targeted awareness training on linked-device and OAuth device-code phishing pretexts for diplomats, journalists, NGO staff, and defense personnel
  • Monitor group chats for duplicate member entries or unrecognized display names as an account-compromise indicator

Timeline of Russian State-Backed UNC5792/UNC4221 Phish EU Officials

  • Google Threat Intelligence Group first documents UNC6293 (ICE RELIC/APT29 sub-cluster) impersonating US State Department personnel to phish diplomats and Russia researchers.
  • Germany's BSI/BfV issue an alert on phishing campaigns 'likely linked to state-controlled actors'; Google TIG separately identifies the UNC7005/Storm-2945 cluster.
  • Dutch AIVD and MIVD publicly attribute a large-scale Signal/WhatsApp linked-device and verification-code phishing campaign to Russian state actors, confirming compromised Dutch government personnel.
  • FBI and CISA issue a joint advisory corroborating the Dutch findings and warning of thousands of compromised commercial messaging accounts.
  • UNC5976's 'CaptiveCrunch' hotel/conference Wi-Fi captive-portal hijacking infrastructure is observed redirecting travelers into phishing flows.
  • Amnesty International Security Lab researcher Donncha Ó Cearbhaill discloses identifying more than 13,500 targets of the campaign via a 'snowball' contact-mining methodology, per TechCrunch.
  • UNC5976 runs a GLOBSEC forum spoof and 'Summit Companion App' lure to distribute the HEADRUSH Excel-plugin malware and commodity infostealers.
  • FBI issues updated advisory PSA I-062626-PSA describing a shift from one-time verification-code theft to direct solicitation of victims' Signal Backup Recovery Keys.
  • US State Department's Rewards for Justice program posts a $10 million reward for information on UNC5792 (FSB Border Guards) and UNC4221 (Russian military intelligence) members.
  • Signal ships a cryptographic hardening fix to the backup recovery key flow in direct response to the disclosed campaign.
  • Google TIG and reporting describe the same actor set expanding into OAuth device-code phishing against academia, aerospace, defense, and think-tank targets.
  • EU Interinstitutional Cybersecurity Board's threat-landscape briefing folds the campaign into its count of 190+ threat actors and 8 significant H1 2026 incidents targeting the EU ecosystem, confirming compromised Dutch government personnel.

Sources cited for Russian State-Backed UNC5792/UNC4221 Phish EU Officials

More in phishing

Detection coverage for TL-2026-2170

As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2170 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats