Government

US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve

UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel.

Hacker reward

The US government is offering rewards of up to $10 million for information on individuals associated with two threat actors linked to Russian intelligence.

Publicly tracked as UNC5792 and UNC4221, the cyber groups have been targeting current and former US government officials and military leaders, allied personnel, journalists, political figures, and key officials located in Ukraine.

The threat actors have been conducting phishing campaigns targeting commercial messaging applications (CMAs), a March alert from CISA and the FBI shows.

Posing as automated CMA support accounts, the hackers lure victims into clicking on a link or sharing verification codes to take over their accounts on messaging platforms such as Signal and WhatsApp.

In a fresh update, CISA and the FBI warn that the attackers have renewed their tactics and are now asking victims for their Backup Recovery Keys to access historical conversations as well, including private and group messages.

“If a victim inadvertently shares their Backup Recovery Key, that same key remains valid even if they create a new account following the compromise using the same phone number. Consequently, the actor could potentially use the compromised key to take over the new account in the future as well,” the alert reads.

Advertisement. Scroll to continue reading.

To evict the hackers from compromised accounts, users need to generate a new Backup Recovery Key, thus invalidating the previous one.

“However, please note that this does not prevent the actor from having already downloaded a backup of the original account,” CISA and the FBI warn.

UNC5792 and UNC4221, the agencies note, are associated with the Russian intelligence services (RIS). On the Rewards for Justice portal, the US government links UNC5792 to the Russian Federal Security Service (FSB) Border Guards, and UNC4221 to the Russian military services.

“Using social engineering techniques, these malicious cyber actors exploit legitimate device-linking features in these secure messaging applications to gain unauthorized access to sensitive government communications, contact lists, and group conversations,” the US notes.

The threat actors have abused the compromised accounts to launch phishing attacks against other valuable individuals, and, in some instances, they modified ‘group invite’ pages to link attacker-controlled devices to victims’ Signal accounts.

The US is willing to pay up to $10 million in rewards for information leading to the identification of UNC5792 actors, including their names, location, and biographies.

It also seeks information on the threat actors’ affiliation with RIS, on entities that support them, their infrastructure and tooling, their funding sources, and financial networks, including banking accounts, cryptocurrency wallets, and transactions.

Related: Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

Related: Russian Initial Access Broker Behind FortiBleed Campaign

Related: Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say

Related: Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

Related Content

Malware & Threats

Turla has been using the backdoor against government and military organizations in Ukraine for espionage.

Cybercrime

Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.

Mobile & Wireless

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.

Cyberwarfare

Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key...

Cyberwarfare

The speech is the latest in a string of warnings from intelligence experts that Russia is stepping up hostile activity in a “gray zone”...

Cybercrime

The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.

Government

Federal prosecutors have been conducting a preliminary investigation since mid-February 2026 into alleged cyberattacks on Signal accounts.

Vulnerabilities

The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version