Monday, August 3, 2026

Apps & Consumer

Security researcher exposes Signal phishing campaign

Security researcher Donncha Ó Cearbhaill exposed a phishing campaign using the 'ApocalypseZ' system to target more than 13,500 Signal users, allegedly linked to Russian government hackers.

Security researcher exposes Signal phishing campaign

Donncha Ó Cearbhaill, a security researcher who heads the Security Lab at the nonprofit Amnesty International, identified a large-scale phishing campaign targeting users of the encrypted messaging platform Signal. Ó Cearbhaill discovered the campaign after becoming a target himself. He recognized the attempt to hack his account and used it as an opportunity to investigate the operation. Through his investigation, he determined that he was one of more than 13,500 targets. The phishing attempt against him began with a deceptive message sent by an account impersonating the Signal Security Support ChatBot, which stated: “Dear User, this is Signal Security Support ChatBot. We have noticed suspicious activity on your device, which could have led to data leak”. The attackers attempted to trick targets into entering a verification code to link their accounts to attacker-controlled devices. Ó Cearbhaill realized that other targets included a colleague and journalists he had worked with, suggesting the hackers used compromised accounts to find new victims.

According to Ó Cearbhaill, the hackers used an automated system called “ApocalypseZ” to run the campaign. This system allowed the operators to automate the attacks and target a large number of people simultaneously with limited human oversight. The codebase and operator interface for ApocalypseZ are in Russian, and the system translated victim chats into Russian. The campaign has been linked to Russian government hackers and Russian government spies. This connection was reported by the Cybersecurity and Infrastructure Security Agency (CISA)—the U.S. cybersecurity agency—alongside the United Kingdom’s cybersecurity agency and Dutch intelligence, which have all warned about the campaign. Additionally, the German news magazine Der Spiegel reported that the campaign compromised several German individuals, including high-profile politicians.

Despite being targeted, Ó Cearbhaill remains unfazed by the hacking attempt. He noted that he is still monitoring the campaign and continues to see active attacks, suggesting the total number of targets is likely higher than the initial figure he identified. To protect against these account hijacking efforts, Ó Cearbhaill advises Signal users to enable the platform’s Registration Lock feature. This security setting requires users to enter a PIN when registering their phone number on a new device, preventing unauthorized transfers even if attackers obtain a verification code.

Why it matters

This incident highlights the evolving sophistication of automated phishing campaigns targeting encrypted messaging platforms and underscores the persistent threat posed by state-sponsored actors.