logoalt Hacker News

cassepipelast Thursday at 3:17 PM1 replyview on HN

No Script is a browser extension. Signal is an Android/Ios/Electron app so no


Replies

aembletonyesterday at 8:30 AM

In each of the fake group invites, JavaScript code that typically redirects the user to join a Signal group has been replaced by a malicious block containing the Uniform Resource Identifier (URI) used by Signal to link a new device to Signal (i.e., "sgnl://linkdevice?uuid="), tricking victims into linking their Signal accounts to a device controlled by UNC5792.

Source: https://cloud.google.com/blog/topics/threat-intelligence/rus...