UNC5792 is a Russian state-linked cyber-espionage threat cluster associated with the Russian Federal Security Service, including officers tied to the FSB Border Guards. Ukrainian defenders track overlapping activity as UAC-0195. The actor has conducted sustained phishing and account-compromise operations against secure messaging users, particularly on Signal and WhatsApp, with a focus on individuals of intelligence value such as U.S. and allied government officials, military leadership, diplomats, journalists, political figures, researchers, civil society organizations, and officials in Ukraine and Armenia. UNC5792’s operations rely on social engineering rather than breaking platform encryption. Reported tradecraft includes impersonation of messaging-platform support personnel, theft of verification codes and account PINs, harvesting of Signal Backup Recovery Keys, and abuse of legitimate device-linking features to hijack or monitor accounts. The group has used malicious or modified group-invite flows and QR-code or link-based lures to connect attacker-controlled devices to victim accounts, enabling access to conversations, contact lists, and group chats. More recent activity has emphasized theft of Signal Backup Recovery Keys, which can allow restoration of encrypted backups and exposure of historical private and group messages, and may support renewed access even after account recreation unless the recovery key is rotated. Compromised accounts have reportedly been used for follow-on phishing and broader intelligence collection. The actor’s targeting and tradecraft are consistent with espionage objectives centered on sensitive government, military, political, and civil-society communications. UNC5792 is frequently discussed alongside UNC4221 as part of related Russian intelligence messaging-app phishing activity, and similar tradecraft has also been associated in public reporting with other Russia-aligned clusters targeting secure communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to widespread phishing campaigns targeting Signal users.
Conducting phishing/social-engineering operations to seize Signal accounts by impersonating support staff and tricking high-value targets into sharing backup recovery keys, verification codes, or account PINs.
Conducting a phishing campaign against Signal users by impersonating Signal support to steal Backup Recovery Keys, and previously seeking account verification codes and Signal PINs.
Conducting social-engineering and phishing campaigns to compromise Signal and WhatsApp accounts, including use of legitimate device-linking features and altered group invite pages to gain unauthorized access to sensitive communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.