LIVE · cybersecurity feed
Live wire
espionagehigh

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Google's Threat Intelligence Group has identified three Russian-linked cyber espionage clusters (UNC6293, UNC7005, and UNC5976) employing sophisticated social engineering tactics. These groups exploit legitimate authentication features like OAuth and app passwords to compromise accounts of researchers, diplomats, and defense personnel. They utilize fake conference invitations, spoofed login pages, and even leverage AI-generated code for malware, posing a significant challenge to traditional security monitoring.

zeroday.news ·

Google's Threat Intelligence Group (GTIG) has identified three distinct Russia-linked cyber espionage clusters, designated UNC6293, UNC7005, and UNC5976, which are targeting researchers, academics, government officials, think-tank analysts, and defense sector personnel in Europe and the United States. These groups employ persistent and adaptive phishing campaigns, leveraging sophisticated social engineering tactics and abusing legitimate authentication features across multiple platforms to compromise personal accounts.

UNC6293, which Google assesses with moderate confidence to be a sub-cluster of APT29 (also known as ICE RELIC), has been active since June 2025. This group focuses on a small number of targets, typically fewer than five at a time, with lures centered on diplomatic events and upcoming conferences. Initially, UNC6293 impersonated US State Department officials to conduct app password phishing. This technique involves convincing a target to set a specific app password that the attacker already knows, allowing them to bypass two-factor authentication. By June 2026, the group had incorporated OAuth phishing, where victims, after logging into a legitimate service, are prompted to share a URL or "verification code," thereby granting attackers valid access tokens.

UNC7005, tracked by Microsoft as STORM-2945, emerged in February 2026 and is also believed to be connected to ICE RELIC. While operating with lower technical sophistication and operational security than UNC6293, UNC7005 utilizes a broader range of tools. Its activities include app password phishing, device code phishing against Microsoft and WhatsApp accounts, malware distribution, and OAuth phishing. The themes for these phishing campaigns often involve invitations for calls with notable organizations or diplomatic events and conferences.

A notable example of UNC7005's tactics is the spoofing of the GLOBSEC conference in May 2026. The actor created a landing page mimicking an invitation to the legitimate forum, collecting detailed registration information, including a fictional wine selection. Targets were then presented with a Microsoft device code to enter. An oversight in the template, which still referenced "Embassy security policy" instead of GLOBSEC, was quickly corrected by UNC7005 after Google flagged the page.

UNC7005 also engaged in WhatsApp phishing by distributing fake pages designed to trick victims into linking their accounts to an attacker-controlled device. These pages offered options such as joining a call, opening an encrypted chat, or downloading a file. If the call option was selected, malicious JavaScript requested microphone and camera access, recording and sending the footage to the attackers. In late May 2026, UNC7005 conducted a broader phishing wave targeting US-based academics, diplomats, and Russia researchers, using a fake "Summit Companion App" to access a document supporting Ukraine. Windows users who downloaded this app received VIDAR, an off-the-shelf infostealer, while Mac users received ATOMIC (AtomicStealer), another commercial macOS infostealer. The email address used in this operation was nearly identical to one used by UNC6293 a year prior.

The hospitality captive portal campaign, previously attributed to Midnight Blizzard by Reliaquest and Microsoft, has been directly linked to UNC7005 by Google. Google traced the infrastructure back to April 2026, identifying domains spoofing Microsoft authentication resources and adding them to Safe Browsing blocklists as they appeared.

The third cluster, UNC5976, is described as being less technically sophisticated than the other two. Google has been tracking domains spoofing Microsoft authentication resources since mid-July 2026, adding them to Safe Browsing blocklists.

espionagephishingoauthrussiasocial engineering
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.