Evolving Threat: Signal Backup Recovery Keys Under Attack
The U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint warning regarding an escalating phishing campaign. This campaign, attributed to Russian intelligence-linked actors, has evolved its tactics to specifically target Signal backup recovery keys. The implications are significant for users relying on Signal for private communication, as the compromise of these keys grants attackers access to encrypted historical message data. The initial phase of this campaign, identified by cybersecurity researchers, focused on acquiring user credentials and potentially Session initiation protocol (SIP) information. However, the threat actors have adapted, now aiming for the cryptographic keys that protect Signal's encrypted backups. These backups, while a convenience for users migrating devices or recovering data, become a critical vulnerability if their associated recovery keys are stolen. Signal employs end-to-end encryption for all communications, meaning messages are secured from sender to receiver. However, backups stored on a user's device or cloud service are encrypted separately, with a user-generated recovery key. If this key is compromised, the attacker can decrypt and read the entire backup. The warning from the FBI and CISA suggests that these sophisticated phishing operations are successfully tricking Signal users into divulging these sensitive keys.
Understanding Signal Backups and Recovery Keys
Signal's backup feature allows users to store their message history locally on their device. This backup is then encrypted with a passphrase or a 30-character recovery key that the user must set up and remember. Crucially, Signal does not store this recovery key on its servers. This design choice enhances privacy by ensuring that even Signal itself cannot access a user's backup data. However, it places the onus entirely on the user to safeguard their recovery key. When a user sets up a new device or reinstalls Signal, they are prompted to enter this recovery key to restore their message history from the backup. The phishing campaign exploits this process. Attackers likely use social engineering tactics, masquerading as official Signal communications or support channels, to convince users that they need to 'verify' or 'update' their backup settings. This often involves directing users to fake websites that mimic Signal's interface, where they are prompted to enter their recovery key. The danger here is twofold. Firstly, the user's historical messages are exposed. Secondly, if the attackers also gain access to the user's active Signal account, they could potentially link the compromised backup to future communications, though Signal's design mitigates this risk to some extent by re-keying new sessions.The Modus Operandi of Russian Intelligence-Linked Actors
While the specific groups behind these attacks are not publicly named in the alert, the FBI and CISA attribute the activity to actors with ties to Russian intelligence services. This is not the first time such groups have targeted secure communication platforms. Their motives are typically espionage, information gathering, and potentially disinformation campaigns. By compromising encrypted communications, these actors gain valuable intelligence on dissidents, journalists, government officials, and other high-value targets. The evolution of the phishing campaign from credential harvesting to targeting backup recovery keys signifies an increasing sophistication and a direct focus on exfiltrating sensitive historical data. This suggests a strategic shift, moving beyond intercepting live communications to accessing a complete archive of past conversations.
Mitigation and Best Practices for Signal Users
Given the nature of this threat, user vigilance is paramount. The FBI and CISA recommend several key actions for Signal users:- Be Skeptical of Unsolicited Communications: Treat any unexpected messages or emails requesting personal information, especially backup recovery keys or credentials, with extreme suspicion. Signal will not ask for your recovery key via email or unsolicited messages.
- Verify Information Sources: Always ensure you are interacting with official Signal channels. Phishing sites often use slightly altered URLs or logos to deceive users.
- Secure Your Recovery Key: Store your Signal backup recovery key offline, in a secure location, such as a password manager or a physical note kept in a safe place. Do not store it digitally in easily accessible locations like cloud storage or unencrypted documents.
- Enable Two-Step Verification (Screen Lock): While not directly preventing recovery key theft, enabling Signal's screen lock feature adds an extra layer of security to your active conversations on your device.
- Regularly Review Account Security: Periodically check linked devices and any security settings within the app to ensure no unauthorized access has occurred.
