Tech
A spyware investigator exposed Russian government hackers trying to hijack Signal accounts
Earlier this year, Donncha Ó Cearbhaill, a security researcher who investigates spyware attacks, found himself in an unusual position. For once, he became the target of hackers.
“Dear User, this is Signal Security Support ChatBot. We have noticed suspicious activity on your device, which could have led to data leak,” read a message he received on his Signal account.
“We have also detected attempts to gain access to your private data in Signal,” the message claimed.
“To prevent this, you have to pass verification procedure, entering the verification code to Signal Security Support Chatbot. DON’T TELL ANYONE THE CODE, NOT EVEN SIGNAL EMPLOYEES.”
Obviously, Ó Cearbhaill, who heads Amnesty International’s Security Lab, immediately recognized that this was an “unwise” attempt at hacking his Signal account. Instead, he thought it’d be a good opportunity to jump into an unexpected investigation.
The researcher told TechCrunch that until then, he had “never knowingly” been targeted with a one-click cyberattack or a phishing attempt like this before.
“Having the attack land in my inbox, and the chance to turn the tables on the attackers and understand more about the campaign was too good to pass up,” he said.
As it turned out, the attempted attack on Ó Cearbhaill was likely part of a wider hacking campaign targeting a large group of Signal users. The hackers’ strategies were to impersonate Signal, warn of bogus security threats, and try to trick targets into giving the hackers access to their account by linking it to a device controlled by the hackers.
Those techniques were exactly the same as those seen in a wider campaign that the U.S. cybersecurity agency CISA, the United Kingdom’s cybersecurity agency, and Dutch intelligence, have all warned of the attacks, and blamed on Russian government spies. Signal, too, has warned of phishing attacks targeting its users. German news magazine Der Spiegel found that the Russian hackers were able to compromise several people inside the country, including high-profile politicians.
Ó Cearbhaill said in a series of online posts that he was able to figure out that he was one of more than 13,500 targets. He declined to reveal exactly how he investigated the hacking attempt and campaign to avoid revealing his hand to the hackers, but shared a few details about what he learned.

First, he realized that other targets included journalists he had worked with, as well as a colleague. At that point, Ó Cearbhaill said he already suspected this was an opportunistic attack where hackers compromised targets and identified new potential victims, thanks to those successful attacks.
Ó Cearbhaill called it a “snowball hypothesis,” and said he is convinced he became a target because he was likely in a group chat with someone who got hacked, which gave the hackers a chance to find the contact information of new targets.
The researcher said he was able to identify the system the hackers were using, which is called “ApocalypseZ,” which automates the attack, allowing the hackers to target many people at the same time in bulk with limited human oversight.
He also found that the codebase and operator interface is in Russian, and the hackers were translating victim chats into Russian, which lines up with the hypothesis that this was the same Russian government hacking group behind similar campaigns.
Ó Cearbhaill said that he’s still monitoring the campaign, and has seen the attacks continue, meaning the total number of targets is certainly much higher than the number he saw earlier this year.
He said he doubts the hackers will go after him again, and probably regret going after him in the first place. He said: “I welcome future messages, especially if they have zero-days they would like to share,” referring to security flaws that are not yet known to the vendor, which are often used in attacks that he investigates.
Ó Cearbhaill said that if Signal users are worried about getting targeted with this type of attack, they should turn on Registration Lock, a feature that lets users set a PIN for their account that prevents others from registering their phone number on a different device.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Planned Amazon data center could become the biggest climate polluter in the U.S.
As part of a planned data center in Pecos County, Texas, Amazon is investing in an on-site power plant that could become the largest source of climate pollution in the United States, according to The New York Times.
The NYT says the plant would burn natural gas and is permitted to release 33 million tons of carbon dioxide per year — more than any other power plant in the U.S.
In a statement, an Amazon spokesperson confirmed that the data center will “be powered by new on-site generation that won’t raise electricity costs for Texas families.” (Data centers face growing political opposition for a number of reasons, including their effect on electricity costs.)
AI has already had a significant impact on Amazon’s carbon emissions, which it reported were up 16% last year — the wrong direction for a company that pledged to eliminate its carbon emissions by 2040. And that could get worse as Amazon and tech companies back the development of huge natural gas plants to support their power-hungry data centers.
The Amazon spokesperson said, “The world looks different now than when we co-founded the climate pledge,” while also claiming, “Our commitment hasn’t changed.”
>
Tech
OpenAI acquires presentation startup NextSlide
NextSlide recently announced that it’s joining OpenAI, with the presentation startup’s team members now working on ChatGPT.
The NextSlide website currently displays a note from founder Ahmed Beshry describing the startup’s product as one “that could turn prompts, notes, documents, or research into a polished, editable presentation.”
The ultimate goal, Beshry said, was “to make visual communication more accessible and help more people express their ideas clearly.” So by joining OpenAI, the team will “continue pursuing that same mission: building AI products that help people create, communicate, and turn their ideas into meaningful work.”
The financial terms of the deal were not disclosed. In a note on LinkedIn, Beshry said the announcement is coming “a few months late,” as the acquisition took place “earlier this year.”
Beshry was previously a co-founder at Caper AI, a smart cart/cashier-less checkout startup acquired by Instacart in 2021.
>
Tech
X replaces ‘misaligned’ revenue sharing program with Original Content Rewards
X, the social media platform now owned by Elon Musk’s SpaceX, is shaking up how it pays influencers and creators.
In announcing the change, the company said it will be winding down its existing Revenue Sharing program and replacing it with something called Original Content Rewards. X will stop accepting new Revenue Sharing participants, while existing participants will continue earning money through September 7.
Then, starting on September 8, they’ll be able to apply for the new program. Participants will still need to subscribe to one of X’s Premium tiers, and there will be qualifying thresholds for follower count (500 verified followers) and impressions (500,000 Home Timeline impressions from verified users in 90 days), but it sounds like the big change is the emphasis on originality.
What counts as original content? X said it can include original reporting and analysis, photos and videos created by the poster, or memes and graphics they’ve designed themselves. Commentary also counts, but “if your content regularly incorporates material created by others, you’ll need to contribute meaningful original value for it to qualify under our original content guidelines.”
The company also included examples of posts that won’t count as original, such as those just copied over from another account, downloaded from one account and re-uploaded to your own, or reposting content “without meaningful transformation.”
This announcement follows repeated attempts by X to reform the Revenue Sharing program, for example reducing payments to aggregators and “clickbait” accounts in April. But these efforts have also prompted complaints from popular accounts profiting from the current system; Musk even reversed some of those changes (giving a creator’s local audience more weight when calculating payouts) after a backlash.
In a post about the new changes, X’s Allegra Jacchia wrote that the existing program “had reached a point where its incentives were misaligned.”
“Creators should be focused on bringing net new content to the platform instead of maximizing payouts,” she said. “We could have kept adding more rules and exceptions, but ultimately the better decision was to start fresh and build a program designed from day one to reward originality.”
Jacchia added that X be “continue refining the program, improving our models, and raising the bar over time.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
-
movies3 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years agoA photo diary of the nightlife scene from LA To Ibiza
