# Russian Intelligence Wages Sustained Phishing Campaign Against Messaging App Users Across Ukraine, Europe, and US


Ukraine's Security Service (SSU) and the FBI have jointly exposed a sophisticated, long-running cyber espionage operation orchestrated by Russian intelligence services targeting messaging app users across government, military, and civil society sectors. The campaign leverages deceptively simple tactics—fake SMS messages impersonating support bots—to harvest credentials from high-value targets in Ukraine, Europe, and the United States.


## The Threat


Russian state-sponsored actors have been systematically sending fraudulent SMS messages to messaging app users, spoofing legitimate support communications from platforms including Signal and WhatsApp. These messages urge recipients to disclose their account credentials, claiming technical issues or security concerns that require immediate verification.


The operation targets a broad swath of victims:


  • Ukrainian government officials and military personnel
  • Politicians and public figures across Europe and the US
  • Civil society activists and journalists
  • Personal accounts of Ukrainian nationals

  • According to the SSU's Telegram announcement, the primary objective is to gain unauthorized access to sensitive military, political, and economic information exchanged through compromised accounts, along with harvesting personal data that could be weaponized for blackmail or further targeting.


    ## Background and Context


    This campaign represents an evolution in Russian cyber espionage tactics. While sophisticated malware and zero-day exploits dominate headlines, Russian intelligence services have demonstrated remarkable success using low-complexity, high-reliability social engineering. The effectiveness of these phishing campaigns against security-aware targets—government officials, military commanders, and activists—underscores a fundamental challenge in cybersecurity: humans remain the most exploitable link, regardless of technical defenses.


    The SSU did not attribute the campaign to a specific threat group, but security researchers have linked similar attack waves to several Russian-aligned threat clusters:


    | Threat Group | Aliases | Known Activity |

    |---|---|---|

    | Star Blizzard | Turla, Snake | Russian APT; long-running espionage campaigns |

    | UNC5792 | UAC-0195 | Ukrainian targeting; messaging app phishing |

    | UNC4221 | UAC-0185 | Messaging security breaches; credential theft |


    The FBI separately disclosed that Russian Intelligence Services (RIS) actors are conducting a parallel phishing campaign targeting users of commercial messaging applications, specifically attempting to trick users into disclosing backup recovery keys—a tactic that would grant attackers persistent access even if passwords are changed.


    ## Technical Details: How the Attack Works


    ### Attack Flow


    The campaign operates through a straightforward but effective social engineering sequence:


    1. Fake SMS Delivery: Attacker sends SMS to target, spoofing the legitimate messaging platform's support number or using lookalike identifiers

    2. Urgency Message: SMS claims account requires verification, reports suspicious activity, or warns of a security threat

    3. Credential Harvesting: Target directed to click a link leading to a phishing page that mimics the genuine platform's login interface

    4. Data Capture: Username, password, and additional authentication factors (if applicable) captured by attacker


    ### Why It Works


    Several factors make this attack vector particularly effective against sophisticated targets:


  • Trusted Channel: SMS feels more official than email phishing to many users
  • Psychological Urgency: Security warnings trigger immediate action
  • Familiar Interface: Spoofed login pages replicate legitimate platforms with high fidelity
  • Low Technical Barrier: No exploit development, malware distribution, or infrastructure exposure required
  • Plausible Deniability: SMS spoofing can be difficult to trace definitively

  • ### Secondary Access Vectors


    Once credentials are compromised, attackers gain:


  • Direct Message Access: Unencrypted or encrypted message history (depending on platform)
  • Contact Lists: Names, phone numbers, and communications patterns of the target's network
  • Account Metadata: Login timestamps, device information, and session data
  • Persistent Access: Ability to add attacker-controlled devices or establish backup recovery options

  • ## Implications for Organizations


    ### National Security Impacts


    The targeting of Ukrainian government and military personnel represents a clear state-sponsored espionage operation. Access to sensitive military communications could reveal:


  • Tactical and operational planning
  • Force disposition and readiness
  • Intelligence assessments and sources
  • Government decision-making processes

  • The inclusion of US and European officials indicates this is not limited to Ukraine—it represents a broader Russian intelligence collection effort against NATO-aligned governments.


    ### Private Sector and Civil Society Risks


    The campaign also targets activists, journalists, and business leaders, suggesting Russian intelligence is collecting intelligence on:


  • Opposition figures and political dissent
  • Civil rights and human rights monitoring
  • Private sector operations and vulnerabilities
  • Transnational networks of influence

  • ## Defensive Recommendations


    Responding to this threat requires both individual and organizational action:


    ### For Users and Organizations


    Immediate Actions:

  • Audit Active Sessions: Review login history and connected devices in messaging app settings; log out of unfamiliar connections
  • Enable Two-Factor Authentication (2FA): Require additional verification factor beyond passwords (though note: SMS 2FA is vulnerable to SIM swapping and interception)
  • Rotate Credentials: Change passwords for messaging apps and associated email accounts
  • Review Account Recovery Options: Disable unused backup recovery methods or security keys

  • Ongoing Hygiene:

  • Verify Requests Out-of-Band: If you receive a suspicious security message, contact the platform directly through an official number or website—never click links in unsolicited messages
  • Refrain from Scanning QR Codes: Unknown QR codes received via message may link to phishing pages
  • Never Share Confirmation Codes: SMS codes, PIN codes, and recovery keys should never be disclosed, regardless of who requests them
  • Educate Teams: Train staff to recognize and report phishing attempts

  • ### For Information Security Teams


  • Network Monitoring: Deploy email and SMS filtering to detect spoofed platform communications
  • Phishing Simulation: Conduct regular phishing campaigns to identify vulnerable staff
  • Incident Response: Establish rapid response procedures for compromised messaging accounts
  • API Integration: Use platform-native APIs to audit for unauthorized sessions or device additions in bulk
  • Threat Intelligence Sharing: Participate in information sharing communities to learn of new phishing campaigns

  • ## HackWire Analysis


    This campaign illustrates a critical paradox in modern espionage: the most sophisticated intelligence services often resort to the simplest attack vectors because they work. While cybersecurity teams invest billions in defending against zero-days and advanced malware, Russian intelligence achieves sustained access through SMS spoofing and social engineering.


    What makes this campaign particularly notable is its scale and persistence. This is not a targeted smash-and-grab operation against a single organization; it's a systematic effort spanning years, multiple countries, and diverse target categories. The fact that it caught the attention of both the Ukrainian Security Service and FBI simultaneously suggests the volume and impact are substantial enough to warrant joint attribution and public disclosure.


    The targeting of messaging apps deserves special attention. Unlike email, which organizations can monitor and filter centrally, messaging apps operate primarily on personal devices outside traditional corporate security perimeters. Messaging is also where officials have grown most comfortable exchanging sensitive information—it *feels* more secure than email because of end-to-end encryption. Russian intelligence appears to be betting that this psychological comfort will lower users' guard precisely where it matters most.


    For defenders, the hard lesson is clear: no amount of encryption or technical security can compensate for a user who voluntarily surrenders their credentials. The defense against this threat requires sustained, culture-wide commitment to credential hygiene and skepticism of urgent security requests—regardless of channel.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Phishing & Social Engineering](https://www.hackwire.news/category/phishing) coverage
  • Cross-reference with [Cyber Espionage](https://www.hackwire.news/category/cyber-espionage) and [Credential Theft](https://www.hackwire.news/category/credential-theft)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)