WeChat worm could pwn a friend before they even answered the call
A Chinese-based phishing campaign is leveraging impersonation of Signal support to trick users into installing malicious software. This follows a broader trend of state-sponsored actors using social engineering to deploy malware, and highlights the ongoing threat of sophisticated attacks targeting vulnerable users.
This report details a phishing campaign originating from Russia, where attackers are posing as Signal support to deceive users into downloading and executing malware. The campaign is part of a larger trend of state-sponsored actors utilizing social engineering tactics to deploy malicious software. The attackers are leveraging the trust associated with Signal, a popular messaging app, to gain access to victims' devices. The exact malware being deployed remains undisclosed, but the campaign demonstrates a persistent and evolving threat landscape.