The Kremlin seeks to compromise this messaging app used by the Ukrainian military, notably through malicious QR codes.

On February 19, 2025, Google’s cybersecurity teams published a report on compromise campaigns launched by Russian-affiliated cybercriminals against Signal. This instant messaging platform is the preferred communication channel of the Ukrainian military due to its high level of end-to-end encryption security.

Groups linked to the Kremlin have notably used malicious QR codes to take control of the application. They embedded them in Signal group invitations, fake security alerts, or phishing emails impersonating Ukrainian military websites.

According to Google, the Russian army has also retrieved Ukrainian soldiers’ phones from the battlefield in an attempt to access their Signal accounts. Additionally, Moscow-affiliated cybercriminal groups have developed a malicious version of the mapping application “Kropyva” to target Ukrainian military personnel.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.