惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
美团技术团队
博客园 - 司徒正美
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
S
SegmentFault 最新的问题
博客园_首页
雷峰网
雷峰网
V
V2EX
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)
量子位
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
Jina AI
Jina AI
月光博客
月光博客
L
LangChain Blog

Truesec

The Ryde Data Breach - Truesec CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223)
Dutch Intelligence Warns of Russian Campaign Against Sign...
2026-03-25 · via Truesec

Threat Insight

The Dutch intelligence and security service AIVD has issued a warning of a large global campaign where Russian cyber espionage actors target users of Signal and Whatsapp to get access to their messaging accounts. The Russian campaign is focused on persuading users to divulge their security verification- and pincodes, allowing the hackers to gain access to the users’ Signal or WhatsApp accounts. [1]

The most frequently observed method used by the Russian hackers is to masquerade as a Signal Support chatbot in order to induce their targets to divulge their codes. The hackers can then use these codes to take over the user’s account. Another method used by the Russian actors takes advantage of the ‘linked devices’ function within Signal and WhatsApp.

At least three Russian threat actors have been linked to this campaign, including the GRU cyber warfare unit known as GRU unit 74455, “Seashell Blizzard” or “Sandworm”. According to AIVD, potential victims include government employees and journalists.

Note that neither the Signal or Whatsapp apps have been hacked. The attack consits of social engineering that tricks the user to let the threat actor gain access to their accounts. It is likely that this campaign has been going on for a considerable time. A similar campaign was reported by Truesec in February 2025 and was also attributed to GRU. [2]

Recommendations

“Sandworm” is most known for their destructive cyber warfare operations, but they have also been involved in cyber espionage and so-called “hack-and-leak” operations where sensitive information is stolen and manipulated to discredit persons and governments.

In their alert, AIVD also published recommendations for how to detect if someone in a Signal group may have been impersonated by someone that has gained access to their account information. [1] The makers of Signal have also published information on how to avoid being tricked by these threat actors. According to Signal they do not use a chatbot that seeks out users unsolicited and will never ask for pin codes if they contact users. [3]

Truesec recommends all users of these apps to familiarize themselves with these recommendations, especially if they belong in any of the listed categories of potential victims.

References

[1] https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign
[2] https://soc.truesec.app/TS-ThreatInsight-2025-9
[3] https://x.com/signalapp/status/2031038277604585785