Google ties three Russian crews to OAuth phishing on academics

Google tracks three suspected Russian clusters abusing OAuth and WhatsApp to hijack targeted accounts.

CSBadmin
2 Min Read

Google’s threat intelligence team is tracking three suspected Russian espionage clusters that lean on legitimate login flows instead of malware to break into personal accounts. The groups, tracked as UNC6293, UNC7005, and UNC5976, are hitting academics, aerospace and defense workers, government staff, and think tanks across Europe, plus U.S. academia.

UNC6293, assessed as a sub-cluster of the APT29-linked Ice Relic operation, has been phishing with fake State Department invitations built around diplomatic conferences, often targeting fewer than five people at a time. In newer campaigns it asks victims to share verification codes or full URLs after a real login to an external provider, which is enough to hand over the account. UNC5976 automates token collection using cloud infrastructure, and the third cluster runs its own phishing infrastructure, with WhatsApp account linking also observed.

Google says the campaigns remain active, with some attacks this month, and that each wave stays small, generally under 100 targets with fewer than 10 confirmed victims. The low volume is by design, aimed at keeping the operations under detection thresholds.

Organizations in the targeted sectors should treat unexpected meeting invitations, especially those referencing State Department events, as phishing lures and require hardware-backed authentication for personal and work accounts.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.