SUBJECT PROFILE
On June 26–27, 2026, the FBI and CISA issued an updated joint advisory (PSA I-062626-PSA) naming two previously untracked Russian Intelligence Services clusters, UNC5792 and UNC4221, behind an evolving campaign to hijack Signal and other commercial messaging app accounts. The actors evolved tactics since a March 2026 advisory, now targeting Signal Backup Recovery Keys to silently restore full account history even after victims change devices. The SSU and FBI confirmed on June 27 that the campaign has compromised thousands of accounts across Ukraine, Europe, and the United States.
Intelligence collection against high-value targets — government officials, military, politicians, journalists — via messaging app account takeover without breaking encryption
OPERATIONAL HISTORY
SMS phishing masquerading as CMA support bots (T1598), Signal Backup Recovery Key theft (T1539), account takeover without breaking E2E encryption, targeting during early morning hours, credential harvesting, lateral phishing from compromised accounts
KNOWN INFRASTRUCTURE
Fake Signal support bots, SMS spoofing infrastructure, multiple RIS-controlled fronts; FSB Border Guards officers confirmed among operators