The images in this article were generated with artificial intelligence. How we publish
Ukrainian and US agencies have exposed a persistent cyber-intrusion campaign aimed at messenger accounts of officials, military, politicians and activists in Ukraine, Europe and the United States. According to the Ukrainian Security Service (SSU) and the FBI, the attackers, linked in other investigations to clusters attributed to Russian intelligence services, have used SMS messages that pose as the "support bot" of the messaging app to convince the victim to deliver credentials, verification codes or recovery keys.
The technique is not new in its concept, but it is new in its refinement and in its objective: targeting high-value personal and professional accounts to extract military, political and economic information or to compromise the chain of confidence of sensitive communications. Recent attacks have combined phishing via SMS with the abuse of active sessions (through code exchange or QR code scanning) and the use of previously committed accounts to distribute information theft malware such as the so-called OYSTERBLUES, attributed to actors aligned with Belarus.

The implications are clear and serious: when an adversary gets access to a message account of a political or military officer, he can monitor conversations, supplant identity to order or disinform interlocutors, and extract attachments or coordinates that compromise operations. In addition, the exfiltration of recovery keys or backups allows for persistent accesses that are not deactivated with a simple password change, which turns these incidents into durable gaps.
From a defensive point of view, it is essential to pay attention to specific behaviour: do not share confirmation codes, PINS or recovery keys, avoid scanning QR sent by unknown and regularly review active sessions in each application to close unknown connections. It is also recommended to limit or disable cloud backup for accounts that handle sensitive information, as such copies may be another exfiltration vector.
For security organizations and officials, the measures must cover both technical and organizational matters. In technical terms, enable strong authentication with physical keys (FIDO2 / WebAuthn) when the application allows, keep up-to-date devices and applications, use mobile device management (MDM) to control sessions and access policies, and deploy abnormal behavior detection focused on login and account configuration changes. At the organizational level, account segmentation (separating personal and professional messaging), continuing training on phishing and clear procedures to verify support requests through official channels are key.

If you suspect an account has been compromised, immediate actions should include closing all sessions from the app settings, changing passwords and recovery keys from a secure device, checking devices for malware and contacting the official service support and the relevant incident response authority. For incidents affecting critical infrastructure or sensitive information, the case should be raised to the response units in your country, such as the Computer Emergency Response National team; in the case of Ukraine there is an official point at https: / / cert.gov.ua.
Personal defense also has practical recommendations: use password managers to generate and store unique keys, prefer physical key authentication over SMS, and set up security and verification notices for new devices. Resources from national agencies and security experts provide guidelines for implementing these practices and assessing the risk of critical accounts; for example, the UK National Cyber Security Centre publishes relevant guidance on https: / / www.ncsc.gov.uk.
Finally, it is important to understand that such campaigns pursue strategic objectives and are integrated into broader intelligence and disinformation operations. The improvement of individual digital hygiene is necessary, but insufficient on its own: it requires corporate policies, investment in operational security and cooperation between technology companies, civil organizations and security agencies to identify, attribute and mitigate these threats in a coordinated manner.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...