FBI seizes domains linked to the Signal phishing campaign CORRECTIV traced to Russia

This is a satisfying follow-up to a good investigation. CORRECTIV earlier traced a campaign hijacking Signal and WhatsApp accounts through fake “Signal Support” messages, Russian hosting infrastructure and a tool called Defisher that had been advertised in Russian hacker forums.

The FBI has now seized 26 domains associated with the campaign, including at least six CORRECTIV previously identified, and attributes the infrastructure to Russian intelligence. Targets included officials, military personnel, journalists and Ukrainian officials; Bundestag president Julia Klöckner was among the German victims. Germany’s federal prosecutor is investigating suspected espionage.

Once victims followed the fake support instructions, attackers could take over accounts, see contacts and read incoming messages. New variants reportedly target Signal backup keys and use compromised accounts to send convincing phishing links to trusted contacts.

The FBI attribution turns what had been strong technical indications of Russian provenance into a much more concrete state-espionage case.