Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
Ukraine's Security Service uncovered a campaign by Russian intelligence to steal messaging credentials via fake support texts. The goal is to gain access to sensitive information.
Intelligence analysis by Llama 3.3 70B

Russian intelligence used fake support texts to trick users into disclosing their messaging app credentials, targeting government officials, military personnel, and activists.
Imagine someone sending you a text message that looks like it's from a messaging app's support team, asking you to give them your login information. That's what's happening in this campaign, where bad guys are trying to trick people into giving away their sensitive information.
Analysis
The Campaign's Modus Operandi
The Russian intelligence campaign involved sending SMS messages that masqueraded as support bots from messaging platforms, urging users to disclose their account credentials. This tactic is a classic example of social engineering, where attackers use psychological manipulation to trick victims into revealing sensitive information.
The campaign's scope was broad, targeting not only government officials, military personnel, and politicians but also personal accounts belonging to Ukrainian nationals. This suggests that the attackers were interested in gathering as much information as possible, regardless of the individual's position or affiliation.
The Threat Actors Involved
While the Security Service of Ukraine did not attribute the campaign to a specific hacking group, similar attack waves have been linked to Russian threat activity clusters such as Star Blizzard, UNC5792, and UNC4221. These groups have been known to target messaging app users, including those using Signal and WhatsApp.
The Consequences of Credential Theft
The theft of messaging credentials can have serious consequences, including the compromise of sensitive information and the disruption of critical communications. In the context of Ukraine, where the country is already facing significant security challenges, the loss of sensitive information could have far-reaching implications for national security.
Mitigating the Risk
To counter the risk posed by such threats, individuals are advised to take several precautions. These include periodically reviewing active messaging app sessions and logging out of unknown connections, enabling two-factor authentication, and refraining from scanning QR codes received from unknown users. Additionally, individuals should not disclose confirmation codes, PIN codes, passwords, and account recovery keys, and should be cautious when clicking on suspicious links or opening files from unknown or dubious chats.
Key points
- Russian intelligence used fake support texts to steal messaging credentials
- The campaign targeted government officials, military personnel, and activists in Ukraine, Europe, and the US
- The goal was to gain access to sensitive information and disrupt critical communications
If individuals and organizations take the necessary precautions, such as enabling two-factor authentication and being cautious with suspicious messages, they can reduce the risk of falling victim to these types of campaigns. Additionally, the exposure of this campaign can raise awareness about the importance of cybersecurity and prompt more people to take action to protect themselves.
The success of this campaign highlights the ongoing vulnerability of individuals and organizations to social engineering attacks. If left unchecked, these types of campaigns can have serious consequences, including the compromise of sensitive information and the disruption of critical communications. Furthermore, the fact that Russian intelligence is involved suggests that the campaign may be part of a larger, more complex operation.


