The Security Service of Ukraine (SSU), in coordination with the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage campaign orchestrated by Russian intelligence services. The operation targeted government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States, aiming to steal sensitive information from messaging accounts.
Attackers sent SMS messages masquerading as official support bots from messaging platforms, tricking victims into disclosing their account credentials. The SSU warned that the goal was to gain access to sensitive military, political, and economic information, as well as personal data. While the agency did not attribute the campaign to a specific hacking group, similar attacks against Signal and WhatsApp users have been linked to Russian threat clusters Star Blizzard, UNC5792 (UAC-0195), and UNC4221 (UAC-0185).
The FBI separately attributed Russian Intelligence Services (RIS) threat actors to an ongoing commercial messaging application (CMA) phishing campaign targeting high-value individuals to steal backup recovery keys. In a related development, CERT-UA attributed a spear-phishing campaign to Belarus-aligned threat actor UNC1151 (Ghostwriter, UAC-0057), which used compromised accounts to deliver the OYSTERBLUES information stealer.
To mitigate such threats, users are advised to review active messaging sessions, enable two-factor authentication, avoid scanning QR codes from unknown sources, and never disclose confirmation codes, PINs, passwords, or recovery keys.
CVEs: CVE-2026-20245
Attack groups: Star Blizzard, UNC5792, UNC4221, UNC1151, Ghostwriter
Malware: OYSTERBLUES
Companies: Security Service of Ukraine, Federal Bureau of Investigation, Computer Emergency Response Team of Ukraine
Original source: thehackernews.com