Signal Phishing Campaign Targets Journalists and Activists to Steal Backup Recovery Keys
2026-05-30T14:51:47Z•56e7f0712821dd59b82f245f29f09bbc13d39f889f40db51b5d7bf82373481ae
AI-assisted-malwareAPTBTMOBGREYVIBEactivistsandroid-ratasocksbotnetcarnivalcisacode-signing-frauddata-breachforticlientfox-tempestjournalistsknown-exploited-vulnerabilitiesphishingrecovery-keysremote-code-executionsignalsocial-engineeringtakedownwindows-zero-dayszero-day-disclosure
What happened
Multiple high-impact cyber stories: a targeted Signal phishing campaign is impersonating Support to trick journalists and activists into handing over backup recovery keys (allowing decryption of full message histories). Dutch authorities dismantled a 17-million-device botnet linked to the Asocks proxy service. Security firm reporting on GREYVIBE details a Russia-linked, AI-assisted APT focused on Ukraine. A researcher publicly released six Windows zero-days (three now exploited), and Fortinet disclosed an actively exploited FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1). Other notable items: a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 56e7f0712821dd59b82f245f29f09bbc13d39f889f40db51b5d7bf82373481ae
- Enrichment time
- 2026-05-30T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.