FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
2026-06-27T07:24:12Z•367afac5ec50c071c61bd51e8065508f1a39356d8f25eb55b63365e8061e35cc
CL-STA-1062Cisco SD-WANCisco Unified CMCobalt StrikeCordyceps CI/CDFortiBleedGaslight macOSGitHub Actions abuseLantronix EDS5000MiasmaMistic backdoorNode.js implantPTC WindchillPhoto ZIP phishingRussian intelligenceSharkLoaderSignal phishingStrikeSharkTinyRCTaccount takeoverbackup recovery keycredential harvestingnpm compromiseprompt injectionsupply chain
What happened
A wide-ranging set of high-risk cyber developments: U.S. authorities (FBI/CISA) updated warnings that Russian intelligence phishers are coercing victims to hand over Signal Backup Recovery Keys to fully restore and take over accounts; multiple active malware and supply‑chain campaigns (SharkLoader/StrikeShark delivering Cobalt Strike, Miasma targeting npm/GitHub Actions and Go packages, TinyRCT backdoor linked to a Chinese-speaking APT, Gaslight macOS with prompt-injection evasion, Mistic backdoor, Node.js implant via photo-themed ZIP phishing against hotels). Several high‑impact software and‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 367afac5ec50c071c61bd51e8065508f1a39356d8f25eb55b63365e8061e35cc
- Enrichment time
- 2026-06-27T07:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.