HomeSecuritySpyware researcher uncovers "Signal phishing campaign"

Spyware researcher uncovers “Signal phishing campaign”

Earlier this year, Donncha Ó Cearbhaill , head of Amnesty International’s Security Lab and a renowned spyware researcher , found himself the victim of a targeted cyberattack for the first time . His experience was particularly unusual, as he is a professional who studies such threats on a daily basis and has helped uncover complex espionage campaigns.

Signal spyware

The attack was triggered by a message he received on his Signal, which presented itself as an official notification from a supposed “Signal Security Support ChatBot.” The message claimed that suspicious activity had been detected on his account and asked for a verification code, while warning him not to share it with anyone.

The attempted deception and the false security narrative

The content of the message followed a classic tactic social engineering, attempting to create a sense of urgency and fear. The attackers claimed that there were attempts to access the user's personal data and that immediate compliance was necessary to prevent a leak.

See also: New vulnerability in PraisonAI: Targeted a few hours after disclosure

However, Ó Cearbhaill quickly recognized the characteristics of a phishing attempt, as Signal does not use such automated chatbots for security purposes. Rather than follow the instructions, he chose to investigate the case, drawing on his experience in analyzing cyberattacks.

Large-scale spyware campaign and high-interest targets

According to its findings, the attempt was not an isolated incident, but part of a broader and organized campaign targeting thousands of Signal users. The attackers used deceptive messages that mimicked official notifications from the platform, with the aim of extracting login codes and linking accounts to devices under their control.

Spyware researcher uncovers "Signal phishing campaign"

This tactic, according to reports from international cybersecurity agencies, has been linked to state-backed groups of attackers, who use sophisticated phishing methods to access sensitive accounts of journalists, activists and government officials.

The “ApocalypseZ” system and the automation of attacks

During his analysis, the researcher identified the use of an automated tool called “ApocalypseZ.” This system allows for the mass dispatch of targeted attacks with limited human intervention, significantly increasing the scale and effectiveness of breach attempts.

See also: Fragnesia: New Linux kernel vulnerability provides root access

Interestingly, both the interface and the tool’s code were in Russian, and victims’ conversations also appeared to be translated into that language for further analysis, raising suspicions that state-sponsored groups may be behind the campaign.

"Chain" spread and the risk of retargeting

One of the most worrying findings of the investigation was that the attack appears to follow a “ snowball effect ” propagation model . When an account was compromised, the attackers gained access to contacts and group chats , creating new potential targets . Ó Cearbhaill himself believes he was targeted because he participated in group chats with already compromised people.

According to the data it collected, the campaign's targets exceed 13,500 cases, with the number constantly increasing as the operation remains active.

Spyware researcher uncovers "Signal phishing campaign"

Reactions and warnings to users

The researcher emphasized that this form of attack relies heavily on human weakness rather than technical vulnerabilities. For this reason, protecting accounts requires additional security measures, such as enabling the Registration Lock feature in Signal, which adds a confirmation PIN for re-registering a phone number on a new device.

At the same time, he emphasized that attacks of this type have not yet been eliminated and continue in real time, which makes user vigilance crucial.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Škoda warns of customer data breach

Ó Cearbhaill’s case highlights the new reality in cybersecurity, where even the most skilled researchers can be targeted by sophisticated phishing campaigns. The combined use of automation, social engineering and state-sponsored tactics shows that the digital threat landscape is becoming increasingly complex, requiring constant adaptation from both platforms and users.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS