PULSE NAME
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
WHITE Signal TheCrowFather 2026-04-10 Modified: 2026-04-10
30
IOCs
MEDIUM VOLUME
Google's Threat Intelligence Group (GTIG) has issued a public warning about Russian-aligned attempts to compromise Signal Messenger accounts used by individuals of interest to Russia's intelligence services in the Ukraine theater of war.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (30)
All IPv4 FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 150.107.31.194 CC=TH ASN=AS131447 popidc powered by csloxinfo 2026-04-10
FileHash-MD5 a97a28276e4f88134561d938f60db495 2026-04-10
FileHash-MD5 b27ff24870d93d651ee1d8e06276fa98 2026-04-10
FileHash-MD5 b379d8f583112cad3cf60f95ab3a67fd 2026-04-10
FileHash-MD5 e078778b62796bab2d7ab2b04d6b01bf 2026-04-10
URL http://150.107.31.194:18000 2026-04-10
domain add-signal-group.com 2026-04-10
domain add-signal-groups.com 2026-04-10
domain confirm-signal.site 2026-04-10
domain group-signal.com 2026-04-10
domain group-teneta.online 2026-04-10
domain groups-signal.site 2026-04-10
domain helperanalytics.ru 2026-04-10
domain signal-confirm.site 2026-04-10
domain signal-device-off.online 2026-04-10
domain signal-group-add.com 2026-04-10
domain signal-group.site 2026-04-10
domain signal-group.tech 2026-04-10
domain signal-groups-add.com 2026-04-10
domain signal-groups.site 2026-04-10
domain signal-groups.tech 2026-04-10
domain signal-protect.host 2026-04-10
domain signal-security.online 2026-04-10
domain signal-security.site 2026-04-10
domain signalgroup.site 2026-04-10
domain signals-group.com 2026-04-10
domain teneta.group 2026-04-10
hostname group.kropyva.site 2026-04-10
hostname teneta.add-group.site 2026-04-10
hostname teneta.join-group.online 2026-04-10