Cyber-intrusion alert by SMS: attackers point to high-value accounts and exfilter recovery keys

Author: Published 3 min de lectura 193 reading

The images in this article were generated with artificial intelligence. How we publish

Ukrainian and US agencies have exposed a persistent cyber-intrusion campaign aimed at messenger accounts of officials, military, politicians and activists in Ukraine, Europe and the United States. According to the Ukrainian Security Service (SSU) and the FBI, the attackers, linked in other investigations to clusters attributed to Russian intelligence services, have used SMS messages that pose as the "support bot" of the messaging app to convince the victim to deliver credentials, verification codes or recovery keys.

The technique is not new in its concept, but it is new in its refinement and in its objective: targeting high-value personal and professional accounts to extract military, political and economic information or to compromise the chain of confidence of sensitive communications. Recent attacks have combined phishing via SMS with the abuse of active sessions (through code exchange or QR code scanning) and the use of previously committed accounts to distribute information theft malware such as the so-called OYSTERBLUES, attributed to actors aligned with Belarus.

Cyber-intrusion alert by SMS: attackers point to high-value accounts and exfilter recovery keys
Image generated with IA.

The implications are clear and serious: when an adversary gets access to a message account of a political or military officer, he can monitor conversations, supplant identity to order or disinform interlocutors, and extract attachments or coordinates that compromise operations. In addition, the exfiltration of recovery keys or backups allows for persistent accesses that are not deactivated with a simple password change, which turns these incidents into durable gaps.

From a defensive point of view, it is essential to pay attention to specific behaviour: do not share confirmation codes, PINS or recovery keys, avoid scanning QR sent by unknown and regularly review active sessions in each application to close unknown connections. It is also recommended to limit or disable cloud backup for accounts that handle sensitive information, as such copies may be another exfiltration vector.

For security organizations and officials, the measures must cover both technical and organizational matters. In technical terms, enable strong authentication with physical keys (FIDO2 / WebAuthn) when the application allows, keep up-to-date devices and applications, use mobile device management (MDM) to control sessions and access policies, and deploy abnormal behavior detection focused on login and account configuration changes. At the organizational level, account segmentation (separating personal and professional messaging), continuing training on phishing and clear procedures to verify support requests through official channels are key.

Cyber-intrusion alert by SMS: attackers point to high-value accounts and exfilter recovery keys
Image generated with IA.

If you suspect an account has been compromised, immediate actions should include closing all sessions from the app settings, changing passwords and recovery keys from a secure device, checking devices for malware and contacting the official service support and the relevant incident response authority. For incidents affecting critical infrastructure or sensitive information, the case should be raised to the response units in your country, such as the Computer Emergency Response National team; in the case of Ukraine there is an official point at https: / / cert.gov.ua.

Personal defense also has practical recommendations: use password managers to generate and store unique keys, prefer physical key authentication over SMS, and set up security and verification notices for new devices. Resources from national agencies and security experts provide guidelines for implementing these practices and assessing the risk of critical accounts; for example, the UK National Cyber Security Centre publishes relevant guidance on https: / / www.ncsc.gov.uk.

Finally, it is important to understand that such campaigns pursue strategic objectives and are integrated into broader intelligence and disinformation operations. The improvement of individual digital hygiene is necessary, but insufficient on its own: it requires corporate policies, investment in operational security and cooperation between technology companies, civil organizations and security agencies to identify, attribute and mitigate these threats in a coordinated manner.

Coverage

Related

More news on the same subject.