DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // RIS-UNC5792-UNC4221-SIGNAL-PHISHINGFIRST SEEN: MAR 2026

RIS Signal Account Hijacking Cluster (UNC5792 / UNC4221)

ALSO KNOWN AS: UNC5792, UNC4221, FSB Border Guards Cyber Unit
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (FSB / GRU attribution)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:MAR 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL78/100
RESOURCES86/100
PERSISTENCE86/100
STEALTH86/100
IMPACT78/100

On June 26–27, 2026, the FBI and CISA issued an updated joint advisory (PSA I-062626-PSA) naming two previously untracked Russian Intelligence Services clusters, UNC5792 and UNC4221, behind an evolving campaign to hijack Signal and other commercial messaging app accounts. The actors evolved tactics since a March 2026 advisory, now targeting Signal Backup Recovery Keys to silently restore full account history even after victims change devices. The SSU and FBI confirmed on June 27 that the campaign has compromised thousands of accounts across Ukraine, Europe, and the United States.

Intelligence collection against high-value targets — government officials, military, politicians, journalists — via messaging app account takeover without breaking encryption

SMS phishing masquerading as CMA support bots (T1598), Signal Backup Recovery Key theft (T1539), account takeover without breaking E2E encryption, targeting during early morning hours, credential harvesting, lateral phishing from compromised accounts

GOVERNMENT
MILITARY
JOURNALISM
CIVIL SOCIETY
UKRAINE

Fake Signal support bots, SMS spoofing infrastructure, multiple RIS-controlled fronts; FSB Border Guards officers confirmed among operators

FILE DATE: MAR 2026
Operation CMA Harvest (Phase 1)
Initial FBI/CISA advisory warned of widespread Signal phishing impersonating support accounts targeting U.S. and international government officials.
FILE DATE: JUN 2026
Signal Recovery Key Escalation (Phase 2)
Updated advisory June 26 names UNC5792 and UNC4221; actors now steal ██████████████████████ Keys, enabling persistent account restoration and full message history access — thousands of accounts compromised globally.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn