A spyware investigator exposed Russian government hackers trying to hijack Signal accounts
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Before you orderOffer from Amazon

Get the latest gadgets delivered free with Prime

  • Fast, free delivery on millions of items
  • Prime Video, Amazon Music and more included
  • Member-only deals all year
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A cybersecurity researcher identified a Russian hacking campaign targeting Signal users, including high-profile individuals. The hackers used phishing tactics and automated tools, with authorities warning of ongoing attacks.

A cybersecurity researcher has exposed a Russian government hacking campaign targeting Signal users, including politicians and journalists, revealing a sophisticated effort to hijack accounts through phishing and automated tools. The campaign’s exposure underscores ongoing cyber espionage efforts by Russian state actors.

Donach Ó Cearbhaill, a security researcher at Amnesty International’s Security Lab, identified an attempted hacking attack on his Signal account in early 2026. He recognized the attack as part of a broader campaign involving Russian hackers using a tool called ‘ApocalypseZ’ to automate phishing and account hijacking on Signal. The hackers impersonated Signal support messages to trick targets into revealing verification codes, enabling them to gain control over accounts.

Ó Cearbhaill estimated that over 13,500 individuals had been targeted, including journalists and colleagues. He observed that the attack infrastructure was in Russian, with the hackers translating victim chats into Russian, aligning with prior assessments linking the campaign to Russian state-sponsored cyber espionage groups. The campaign appears to be ongoing, with attacks continuing beyond his initial detection.

Why It Matters

This development highlights the persistent threat posed by Russian government hackers to digital communications security, especially targeting encrypted messaging platforms like Signal used by journalists, politicians, and activists. The campaign’s scale and sophistication demonstrate the importance of cybersecurity vigilance and the potential for espionage, data theft, or political manipulation.

Amazon

Signal account security key

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

Earlier this year, Western cybersecurity agencies, including CISA and UK cybersecurity authorities, issued warnings about Russian hacking groups targeting Signal and other encrypted platforms. German media also reported that Russian hackers had compromised several high-profile figures within Russia. The use of automated tools like ApocalypseZ marks a shift toward larger, more efficient campaigns designed to exploit trusted communication channels.

“The attack on my Signal account was likely part of a larger, automated campaign targeting thousands, including journalists and officials.”

— Donncha Ó Cearbhaill

“The use of Russian-language code and translation of chats strongly indicates Russian state involvement, consistent with prior assessments.”

— Cybersecurity analyst familiar with the campaign

Amazon

phishing protection software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

While the campaign’s infrastructure and scope are partially understood, the full extent of targets and specific operational details remain unclear. It is also uncertain whether the hackers have been fully disrupted or if they plan further attacks.

Amazon

encryption and privacy tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

Authorities and cybersecurity firms are expected to continue monitoring the campaign, with potential updates on arrests or takedowns of hacking infrastructure. Signal has advised users to enable Registration Lock and remain vigilant against phishing attempts. Further investigations into the hackers’ operations are anticipated.

Amazon

two-factor authentication security device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How do hackers hijack Signal accounts?

They send phishing messages impersonating Signal support, trick targets into revealing verification codes, and then use automated tools to link the account to a device controlled by the hackers.

What is ApocalypseZ?

It is an automated hacking tool used by the Russian hackers to target multiple Signal users simultaneously, enabling large-scale phishing campaigns with limited human oversight.

Are Signal users safe from these attacks?

Users can reduce risk by enabling the Registration Lock feature, which requires a PIN to register the account on new devices, and by being cautious of suspicious messages.

What is the significance of this campaign?

This campaign exemplifies the ongoing cyber espionage efforts by Russian state actors targeting encrypted communications, with implications for political, journalistic, and personal privacy security worldwide.

Will the hackers be stopped?

Authorities and cybersecurity firms are actively investigating and working to disrupt the campaign, but the full scope of their operations and future plans remains uncertain.

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Your Coding Agent Is an Attack Surface: The Claude Code Security Reckoning

Recent security flaws in Claude Code reveal critical attack surfaces, risking token theft and code execution for developers using agentic AI tools.

Navigating the Dark Web: What It Is and Why It Matters

Curious about the dark web’s hidden world and its significance? Discover what lies beneath and why it truly matters.

Cybersecurity Compliance 2025: Key Regulations to Know

Guidelines for cybersecurity compliance in 2025 reveal critical regulations shaping data security, but staying ahead requires understanding evolving standards and practices.

Are AI Sovereignty Certifications Reliable? The 24% Rule Provides Clues

An analysis of the reliability of AI sovereignty certifications, focusing on the 24% ownership rule and its implications for data control and legal sovereignty.