Phishing to Signal users steals the recovery key

Author: Published 3 min de lectura 182 reading

The images in this article were generated with artificial intelligence. How we publish

The joint FBI and CISA public alert on a phishing campaign for Signal users represents a remarkable evolution of tactics: it is no longer just about stealing verification codes or linking devices, but about inducing victims to deliver their Backup Recovery Key, the key to decipher the protected backup in Signal's cloud.

Those responsible, attributable by the agencies to Russian intelligence services and publicly traced as UNC5792 and UNC4221 they have focused their messages on people of high interest: public officials, military, journalists and political figures, especially with links to Ukraine. The social engineering used simulates official communications from Signal support, claiming security changes or data loss to justify the user to copy and paste his recovery key.

Phishing to Signal users steals the recovery key
Image generated with IA.

It is important to understand the technical vector behind the deception: Signal offers encrypted backup whose encryption is linked to a user-generated recovery key; anyone who gets that key can restore and read the message history even if he has not compromised end-to-end protection in transit. Signal explained the design of that function on his official blog: Introduction to Secure Backups.

The implications are clear and dangerous: the historical confidentiality of conversations ceases to depend only on the messaging channel and goes through the secret of the backup key. Generate a new, invalid key for future downloads, but does not prevent an attacker already in possession of the key from downloading and retaining copies of the backups. The FBI notes this clarification in its public notice: FBI PSA on the campaign.

From a practical perspective, attackers use a stable pattern: first message that urges to create or activate backup, second message that simulates a synchronization problem and literally requests that the user stick the key to the chat to "recover" the data. That gesture is the voluntary delivery of the key that allows deciphering out of the owner's control.

For users and security equipment the recommendation is double: technical measures and operational habits. In technical terms, consider deactivating cloud backup if you communicate extremely sensitive information, or at least protect the device with strong lock and not store the key in clear text. In operational terms, never share codes or keys through chats, check support communications through official channels and immediately record any suspicious activity in related accounts.

Phishing to Signal users steals the recovery key
Image generated with IA.

If you suspect your key was compromised, generate a new backup key from Signal's options and assume that any previous backup may have been downloaded by third parties; change number not automatically invalidated old keys. In addition, review the devices linked to Signal and close unknown sessions, and launch additional controls on the device (strong screen lock, device encryption, and minimum applications with access to clipboard).

Organizations should complement these recommendations with specific training on targeted phishing, simulations of attacks to measure resilience and response procedures that include notification to authorities. Victims or organizations that detect incidents should report it to the FBI IC3 or CISA, for example through the CISA response form and incident reports: CISA Incident Reporting and consider contact with the FBI regional office for investigation.

Finally, this campaign recalls that real security combines robust cryptography with prudent human practices: the best encryption can be overturned by a convincing message. Maintaining the security position requires reducing the surface of deception (less copies in the cloud where possible), verifying the authenticity of sensitive requests and treating recovery keys as critical information that should never be shared.

Coverage

Related

More news on the same subject.