Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Vivo V60 5G India Launch Date Set for August 12; Colour Options and Key Features Revealed

1 August 2025

OnePlus 11 5G Gets New OxygenOS 15 Update in India With New Features, Latest Security Patch

1 August 2025

Cronos: The New Dawn Is Coming To All Platforms Including Switch 2 In September

1 August 2025
Facebook X (Twitter) Instagram
Just In
  • Vivo V60 5G India Launch Date Set for August 12; Colour Options and Key Features Revealed
  • OnePlus 11 5G Gets New OxygenOS 15 Update in India With New Features, Latest Security Patch
  • Cronos: The New Dawn Is Coming To All Platforms Including Switch 2 In September
  • Silent Hill f Preview – When Beauty Is The Beast
  • Apple Has Shipped 3 Billion iPhone Units Since Launch in 2007, Says CEO Tim Cook
  • Infinix GT 30 5G+ Confirmed to Launch in India Soon; Cyber Mecha Design 2.0 Teased
  • Measles Cases Are Soaring in Mexico
  • Review: Asus Chromebook CX14
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » A Signal Update Fends Off a Phishing Technique Used in Russian Espionage
News

A Signal Update Fends Off a Phishing Technique Used in Russian Espionage

News RoomBy News Room19 February 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

For more than a decade now, Russian cyberwarfare has used Ukraine as a test lab for its latest hacking techniques, methods that often target Ukrainians first before they’re deployed more broadly. Now Google is warning of a Russian espionage trick that’s been used to obtain Ukrainians’ messages on the encrypted platform Signal—and one that both Ukrainians and other Signal users worldwide should protect themselves against with a new update to the app.

Google’s threat intelligence team on Wednesday released a report revealing how multiple hacker groups that serve Russian state interests are targeting Signal, the end-to-end encrypted messaging tool that has become widely accepted as a standard for private communications and is now often used by Ukrainians, including in the Ukrainian military’s battlefield communications. Those Russia-linked groups, which Google has given the working names UNC5792 and UNC4221, are taking advantage of a Signal feature that allows users to join a Signal group by scanning a QR code from their phone. By sending phishing messages to victims, often over Signal itself, both hacker groups have spoofed those group invites in the form of QR codes that instead hide javascript commands that link the victim’s phone to a new device—in this case, one in the hands of an eavesdropper who can then read every message the target sends or receives.

“It looks exactly like a group invite, and everything would function exactly like that, except when you scan it, it links the device out,” says Dan Black, a Google cyberespionage researcher and former NATO analyst. “It instantly pairs your device with theirs. And all your messages are now, in real time, being delivered over to the threat actor while you’re receiving them.”

Two months ago, Google began warning the Signal Foundation that maintains the private communications platform about Russia’s use of the QR code phishing technique, and Signal last week finished rolling out an update for iOS and Android designed to counter the trick. The new safeguard warns users when they link a new device and checks with them again at a randomized interval a few hours after that device is added to confirm that they still want to share all messages with it. Signal now also requires a form of authentication such as entering a passcode or using FaceID or TouchID on iOS to add a new linked device.

In fact, Signal had already been working to update those forms of phishing protections aimed specifically at exploitation of its linked device feature prior to Google’s warning, says Signal’s senior technologist, Josh Lund. But Google’s report about Russia’s spying in Ukraine provided an “acute” example of the problem that pushed them to move quickly to protect users, he says.

“We’re really grateful to the Google team for their help in making Signal more resilient to this type of social engineering,” says Lund, using the cybersecurity term for tricks that deceive victims into giving hackers sensitive information or access to their systems.

Both Google and Signal emphasized that the phishing technique Google has seen in use in Ukraine doesn’t suggest that Signal’s encryption is broken or that the app’s messages can otherwise be eavesdropped in transit. Instead, the trick essentially combines two legitimate features—QR-code group invites and QR-code device linking that pairs a smartphone with a laptop—invisibly swapping one with the other to deceive users. “Phishing is a big problem on the internet, and it’s never nice to hear that someone has fallen victim to one of these attacks,” Lund says. “But we’re trying to do our best to keep users safe, and we think these recent improvements will really help.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThis Lenovo ThinkPad is normally $3,229 — today it’s $1,453
Next Article News flash: Every size of the Samsung Q60D QLED TV is on sale today

Related Articles

News

Measles Cases Are Soaring in Mexico

1 August 2025
News

Review: Asus Chromebook CX14

1 August 2025
News

A New Katamari Game, Octopath Traveler 0, and More Are Coming to Switch 2

31 July 2025
News

Inside the Summit Where China Pitched Its AI Agenda to the World

31 July 2025
News

States Are Moving to Protect Access to Vaccines

31 July 2025
News

Still Using Windows 10? Here’s How to Get Another Year of Updates for Free

31 July 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024103 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

Oppo Reno 14, Reno 14 Pro India Launch Timeline and Colourways Leaked

27 May 202582 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Phones

Infinix GT 30 5G+ Confirmed to Launch in India Soon; Cyber Mecha Design 2.0 Teased

News Room1 August 2025
News

Measles Cases Are Soaring in Mexico

News Room1 August 2025
News

Review: Asus Chromebook CX14

News Room1 August 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025126 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024103 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Silent Hill f Preview – When Beauty Is The Beast

1 August 2025

Apple Has Shipped 3 Billion iPhone Units Since Launch in 2007, Says CEO Tim Cook

1 August 2025

Infinix GT 30 5G+ Confirmed to Launch in India Soon; Cyber Mecha Design 2.0 Teased

1 August 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.