Ukraine, FBI Uncover Russian Intelligence Campaign Targeting Messaging Accounts

Ukraine’s Security Service and the FBI have uncovered a long-running campaign by Russian intelligence services to break into the messaging accounts of government officials, military personnel, and activists across Ukraine, Europe, and the U.S.

The attackers send SMS messages disguised as support alerts from messaging platforms, tricking users into handing over their account credentials. The goal: access to sensitive military, political, and economic information flowing through these channels.

“The goal of these hacks is to gain access to sensitive military, political, and economic information exchanged by users, as well as to steal their personal data,” the SSU warned in a Telegram post. The campaign targets not just organizations and public figures but ordinary Ukrainian nationals too.

The SSU didn’t attribute the campaign to a specific group, but similar attacks targeting Signal and WhatsApp users have been linked to Russian threat clusters tracked as Star Blizzard, UNC5792 (UAC-0195), and UNC4221 (UAC-0185).

The FBI recently attributed a separate commercial messaging phishing campaign to Russian Intelligence Services, aimed at high-value targets to steal backup recovery keys. Late last month, Ukraine’s CERT-UA tied the Belarus-aligned UNC1151 (Ghostwriter) to a spear-phishing campaign using compromised accounts to deliver an information stealer called OYSTERBLUES.

Basic defenses still matter: review active messaging sessions regularly, enable two-factor authentication, don’t scan QR codes from unknown contacts, and never share confirmation codes or passwords.