Social justice warrior and spyware investigator Donncha Ó Cearbhaill found himself targeted by hackers earlier this year. But instead of panicking, he turned the tables on his attackers, revealing a wider hacking campaign linked to Russian government spies.
Using Signal’s security support chatbot as bait, the hackers warned Ó Cearbhaill that his device was leaking data and demanded access to his account via a verification code. Recognizing this as an opportunistic attack, he instead embarked on investigating the hacking attempt.
The researcher discovered that over 13,500 people were targeted in a similar manner. He identified the automated system used by the hackers, called “ApocalypseZ,” which allowed them to target many users simultaneously with limited human oversight. The codebase and operator interface was found to be in Russian, suggesting a connection to a known Russian hacking group.
Ó Cearbhaill now monitors the ongoing campaign, warning Signal users about the risks of phishing attacks and advising them to enable Registration Lock to prevent unauthorized use of their accounts on different devices. He remains unconcerned about future attempts against him, viewing it as a small price for more knowledge about this cyber threat.







