Hackers are targeting Signal users in a new phishing campaign that tries to steal their chat backup recovery keys, according to TechCrunch.

The attack involves messages that pretend to come from Signal’s support team and warn users that their backed-up chats and media may be permanently lost because of a fake sync issue.

Washington Post analyst Josh Rogin shared a screenshot of one of these messages on Wednesday. The message claimed that users needed to share their recovery key to link their existing backup to their account. It also warned that failing to do so could lead to losing access to the account and stored data. The fake message appeared to come from an account named “Signal Support.”

Rogin said several anti-Chinese Communist Party activists had received the malicious message. Mohammed Al-Maskati, director at Access Now’s Digital Security Helpline, told TechCrunch that two other people had shared similar messages with him, and they were not Chinese activists. This suggests the campaign may be broader than one specific community, or that different hacking groups are using the same method.

It is still unclear how successful the campaign has been. Al-Maskati said stealing someone’s recovery key is only one part of the attack, because hackers would still need to take over the victim’s Signal account. But the strategy is dangerous because it uses phishing, meaning attackers try to trick users into giving away private information by pretending to be someone trustworthy.

READ
Spain Busts €140 Million Cybercrime Ring Behind BEC and Investment Fraud

Signal has clearly warned users that it will never contact them first and will never ask for their registration code, PIN, or recovery key. Any message claiming to be from “Signal Support” and asking for these details should be treated as malicious. Signal had already warned about this type of attack last month.

This new campaign is different from previous Signal attacks because it specifically targets backups. These backups can include old chats, photos, documents, and other media. Earlier attacks usually focused on hijacking a user’s account and impersonating them, often to contact other people from the victim’s account. In those cases, hackers typically could not see older messages because Signal does not automatically transfer past messages to a newly registered device.

Signal’s Secure Backups feature, launched last year, allows users to upload encrypted account data to Signal’s servers. The backup is protected by a recovery key that Signal says never leaves the user’s device and is never shared with its servers. Without that recovery key, neither Signal nor anyone else can read, decrypt, or restore the backup.

That is why hackers are now trying to trick users into handing over the key themselves. Signal says users should store their recovery key safely, such as in a notebook or password manager, and never share it with anyone.


Buy ExpressVPN with PayPal or Credit Card

Advertisement