“Because linking an additional device typically requires scanning a quick-response (QR) code, threat actors have resorted to crafting malicious QR codes that, when scanned, will link a victim’s account to an actor-controlled Signal instance.”

Russian groups are not breaking Signal’s encryption. They trick users into scanning a QR code that links an attacker’s device. Every new message then goes to both phones. Nothing alerts the victim.