메뉴
BL
Ars Technica 29일 전

미 국무부, 시그널·왓츠앱 해킹 러시아 해커 정보에 1000만 달러 현상금

IMP
8/10
핵심 요약

미 국무부는 언론인과 정부 관계자 등의 시그널(Signal) 및 왓츠앱 계정을 해킹한 러시아 국가 지원 해커 그룹(UNC5792, UNC4221)의 정체나 위치를 알려주면 최대 1000만 달러의 현상금을 지급한다고 발표했습니다. 이들은 고객 지원 봇을 사칭하거나 백업을 유도하여 사용자의 인증 코드와 복구 키를 탈취한 뒤 과거 대화 내용까지 모두 가로채는 정교한 피싱 및 사회공학적 공격을 감행하고 있습니다. 기업 및 실무자들은 메신저의 공식 지원 센터를 사칭한 접근이나 인증 코드/복구 키 탈취 시도에 대해 각별한 주의와 보안 교육이 필요합니다.

번역된 본문

미 연방 당국은 탐사보도 언론인과 미국 정부 직원의 수천 개의 시그널(Signal) 및 왓츠앱(WhatsApp) 계정을 탈취한 러시아 국가 지원 사이버 그룹의 신원이나 위치를 확인할 수 있는 정보에 대해 최대 1,000만 달러의 현상금을 내걸었다.

이 공격 작전은 적어도 3월부터 활동해 왔으며, 당시 미국 연방수사국(FBI)은 러시아 정보기관과 관련된 공격자들이 고가치 표적을 노린 진행 중인 피싱 캠페인에 대해 경고하는 자문을 게시했다. 자동화된 고객 지원 메시지를 가장한 메시지들은 사용자에게 링크를 클릭하거나 인증 코드 또는 계정 비밀번호를 제공하도록 요구한다. 만약 사용자가 이에 응하면, 자신도 모르게 공격자의 기기를 본인 계정에 연결(Link)하게 되거나 계정이 완전히 탈취되어 접근이 차단된다.

수천 개의 계정 이미 탈취됨 이를 통해 공격자는 탈취된 계정으로 전송되는 모든 새로운 메시지를 읽을 수 있다. 하지만 시그널에 내장된 안전 기능 덕분에 공격자는 기존에 진행했던 대화 내용은 읽을 수 없었다. 이러한 피싱 메시지는 현재 및 전직 미국 정부 관료, 군인, 정치인, 언론인과 같은 '情报 가치가 높은 사람들'에게 주로 발송되었다.

지난주 FBI는 이 캠페인이 진화했다고 밝히는 업데이트를 게시했다. 수신자를 속여 자신의 계정을 공격자 기기에 연결하도록 유도하는 지원 봇으로 위장하는 것 외에도, 메시지들은 사용자들에게 '이 지시사항에 따라 모든 기존 대화 내용을 백업'하도록 강력히 촉구한다. 이어서 후속 메시지는 표적에게 시그널 서버에 저장된 백업 파일을 암호화하는 데 사용되는 긴 암호인 '복구 키(Recovery key)'를 전송하도록 지시한다. 이 키를 넘겨주는 순간, 공격자는 과거 시그널 대화 내역에 접근할 수 있게 된다.

이 업데이트에 따르면, 이 공격에 책임이 있는 것으로 파악된 두 개의 러시아 정부 지원 그룹은 'UNC5792' 및 'UNC4221'로 추적되고 있다. 실제 발송된 피싱 메시지 중 하나의 내용은 다음과 같다:

[시그널 공지사항] 최당 제3자 기기를 계정에 연결하여 당사 메신저 사용자를 해킹하려는 시도가 잦아지고 있습니다. 미국 정부 및 유럽 파트너들과 함께 수사한 결과, 해당 계정에 대한 공격은 이란 및 구 소련 국가 출신 해커들에 의해 자행된 것으로 드러났습니다. 이에 따라 시그널은 서비스 약관 및 개인정보 처리방침을 업데이트하며, 사용자에게 필수 '2단계 인증'을 도입합니다. 메시지와 미디어를 잃지 않으려면 시그널 백업을 설정하십시오 (설정 -> 백업 -> 백업 활성화 -> 복구 키 보기 -> 클립보드에 복사 -> 다음 -> 복구 키 입력 -> 다음 -> 계속 -> 백업 계획 선택). 팝업창의 '동의' 버튼을 클릭하고 당사 메신저의 보안 업데이트를 계속 확인하십시오. 안전을 유지하고 종단 간 암호화를 지원하는 가장 안전한 메신저를 사용해 주셔서 감사합니다. 질문이 있는 경우 /help를 보내주십시오.

또 다른 메시지의 내용은 다음과 같다:

[조치 필요: 데이터 복구 요청됨] 동기화(Sync) 문제로 인해 귀하의 시그널 계정 데이터(메시지 및 미디어)가 영구적으로 손실될 위험에 처해 있습니다. 메시지와 미디어 손실을 방지하려면:

  1. 설정 -> 백업 -> 구성 -> 백업 활성화 -> 복구 키 보기로 이동합니다.
  2. 복구 키를 클립보드에 복사합니다.
  3. 이 채팅창에 해당 키를 붙여넣습니다. 이 작업은 기존 백업을 귀하의 계정에 연결합니다. 이를 수행하지 않으면 계정 및 저장된 모든 데이터에 액세스하지 못할 수 있습니다.

월요일, 미 국무부는 이 캠페인에 관여한 사람들의 신원이나 위치에 대한 정보를 제공하는 경우 최대 1,000만 달러의 현상금을 지급하겠다고 밝혔다. 이 현상금은 미 국무부의 '정의를 위한 현상금(RFJ, Reward for Justice)' 프로그램을 통해 제공된다.

게시물에 따르면, 일부 경우 공격자들은 사용자가 다른 사람을 그룹 대화에 초대할 수 있는 링크를 만드는 시그널의 기능을 악용하기도 했다. 이번 현상금 제도와 관련된 국무부 게시물은 다음과 같이 명시하고 있다: "이 현상금 제도 하에, RFJ는 러시아 연방보안국(FSB) 국경수비대와 관련된 악성 사이버 그룹인 UNC5792, 그리고 악성 사이버 행위자 그룹인 UNC4221에 대한 정보를 찾고 있다."

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees. The operation has been active since at least March, when the FBI published an advisory warning of ongoing phishing campaigns targeting high-value targets by attackers associated with Russian intelligence services. Messages masquerading as automated support communications ask that users click a link or provide verification codes or account passcodes. In the event the user complies, they unknowingly link the attacker’s device to their account or have their account completely taken over and are locked out. Thousands of accounts already compromised With that, the attackers can read any new messages sent to the compromised account. A safety feature built into Signal, however, prevents the attackers from reading any previous conversations. The messages are sent to “individuals of high intelligence value, such as current and former US government officials, military personnel, political figures, and journalists.” Last week, the FBI published an update that said the campaign had evolved. In addition to trying to post as support bots trying to trick recipients into linking their account to an attacker device, the messages also urge users to create a backup of all previous communications following the directions here. A follow-up message then instructs the targets to send the long passcode that’s used to encrypt backups stored on Signal servers. With that, the attackers have access to past Signal conversations. The update said two Russian government groups responsible were tracked as UNC5792 and UNC4221. One message has text similar to this: Signal is here Recently, attempts to hack users of our messenger with the connection of third-party devices to the account have become more frequent. An investigation conducted jointly with the US government and European partners revealed that the attacks on accounts were carried out by hackers from Iran and post-Soviet countries. In this regard, Signal updates Terms of Service & Privacy Policy, and introduces Mandatory Two-factor Verification for users. Not to lose your messages and media, set up your Signal Backup (Settings -> Backups -> Enable backups -> View recovery key -> Copy to clipboard -> Next -> Enter the recovery key -> Next -> Continue -> Choose your backup plan). Click the “Accept” button in the pop-up and stay tuned for security updates on our messenger. Stay safe and thank you for using the most secure messenger with end-to-end encryption. If you have any questions, send /help Other text looks like this: Action Required: Data Recovery Needed Your Signal Account data (messages and media) is at risk of permanent loss due to a sync issue. To avoid losing your messages and media: Go to Settings -> Backups -> Configure -> Enable Backups -> View Recovery Key. Copy the recovery key to your clipboard. Paste the key into this chat. This links your existing backup to your account. Failure to do this may result in losing access to your account and all stored data. On Monday, the US State Department said it was offering up to $10 million for information on the identities or locations of any of the people involved in the campaign. The reward is being offered under the State Department’s Reward for Justice program, or simply RFJ. The post said that in some cases, the attackers were abusing a Signal feature that allows users to create links to invite others to group discussions. “Under this reward offer, RFJ is seeking information on UNC5792, a malicious cyber group associated with the Russian Federal Security Service (FSB) Border Guards and UNC4221, a malicious group of cyber actors working on behalf of the Russian military services,” Monday’s post read. “UNC5792 has conducted widespread phishing campaigns targeting Signal and WhatsApp accounts of US government officials, military leadership, and allied personnel.” The post continued: In some instances, UNC5792 actors altered legitimate “group invite” pages to redirect users to a malicious URL that linked a UNC5792-controlled device to the victim’s Signal account. Although these malicious cyber activities did not exploit any security vulnerability in the platforms’ encryption protections, they have compromised thousands of individual commercial messaging application accounts. The RFJ went on to say that the campaign has already compromised thousands of messenger accounts. It may be hard for many to fathom the possibility of US intelligence officers, diplomats, or journalists falling for the scam. The fact remains that it only takes a moment for someone who is fatigued, sleep-deprived, or otherwise unguarded to act on the messages. Phishing remains one of the most effective means of gaining access to accounts, despite the relatively unsophisticated technical prowess required. If someone provides their backup key in their response, they must generate a new backup recovery key. “To mitigate this risk, the user must generate a new Backup Recovery Key within the Settings control; this action will invalidate the previous key for all future backup downloads,” the FBI said in last week’s advisory. “However, please note that this does not prevent the actor from having already downloaded a backup of the original account.” Messenger users should note that: Legitimate CMA support services will not request verification codes within the application. CMA support services do not send users links to “verify” or “restore” accounts. They should never provide a verification code without confirming the request comes from a legitimate CMA communication channel. As always, it’s a good idea to resist taking on the feeling of urgency that’s often conveyed in such messages. There is rarely a penalty for waiting an extra hour or two to act, even when responding to legitimate requests. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 10 Comments